The attackers are sending phishing emails purporting to be from the Palestinian Political and National Guidance Commission. Attached to each message is a self-extracting archive file that contains a malicious executable and a Word document. The modular malware can take screenshots of the infected machine and send them to the command-and-control server, locate and send a list of documents with file extensions. The threat actor is now dubbed “Big Bang” because some of the malware’s modules were named after characters in the television show “The Big Bang Theory””]

