Security experts from AlienVault have spotted a new piece of malware named GZipDe that was used in a cyber-espionage campaign. The malware was detected after user from Afghanistan has uploaded a weaponized Word document on VirusTotal service. VirusTotal doesn’t share information about the source of the upload and the target of the attack was not disclosed. The attack chain starts with a spear-phishing message spreading the weaponized document, the final goal appears to be the delivery of a Metasploit backdoor. GZipde is downloader that is used by threat actors to fetch other payloads from a server controlled by attackers.”]
Source: https://securityaffairs.co/wordpress/73802/malware/gzipde-downloader-metasploit-backdoor.html

