Skip to main content
Advertisement
Live broadcast
Main slide
Beginning of the article
Озвучить текст
Select important
On
Off

Online fraudsters can use document templates to deceive Russians, experts have warned about this. People in the search engine follow the first links to download standard forms, which attracts intruders to create websites disguised as official ones. For more information about how fraudsters use document templates to deceive Russians, how dangerous such schemes are and how to protect themselves from them, read the Izvestia article.

What is the topic of document templates interesting to scammers?

Accountants, lawyers and HR specialists work daily with standard forms, which are periodically updated and supplemented, Dmitry Zubarev, director of the Analytical Center of the IT company Ural Center for Security Systems, said in an interview with Izvestia. In modern corporate IT systems, there are services with up-to-date templates and reference materials, but some employees still rely on examples available on the Internet.

"This is what sets the stage for attacks: a potential victim goes to the website and downloads a document, being sure that the resource is legitimate and its use is safe," says the expert.

Accounting, legal and personnel templates are documents that users download in a hurry and without much caution, explains Alexey Mironov, Product Director of Stakhanovets, an expert in the field of IT and artificial intelligence (AI).

Reconciliation reports, contracts, power of attorney, and reporting forms, according to the expert, are needed "here and now," often under a deadline. This reduces vigilance: users think less about checking file sources, and more about how to close work tasks faster. In addition, the target audience of such attacks is highly specialized and predictable — accountants and lawyers regularly search for the same standard forms, which allows attackers to accurately target lures through SEO promotion of fake sites or contextual advertising.

What schemes on the topic of document templates to expect in 2026

Today, there are a wide variety of sites on the Web offering malicious software (VPO) for downloading under the guise of useful files, says Alyona Yartseva, an analyst at the analytical research department at Positive Technologies. According to her, this scheme is well-known, tested and very successful, so it is unlikely to undergo dramatic changes in the coming year.

Presentation templates, law files, requirements for business organization companies, fire requirements and other documentation that employees can use can act as decoy files," the Izvestia interlocutor notes.

In addition, according to the expert, we can expect the appearance of new bait files of various types (for downloading templates, applications, documents), but they all have the same goal - to gain access to users' devices through the door they open. In turn, Alexey Mironov admits that in the future, further complication of disguise is likely: malicious files will increasingly be designed to meet current regulatory changes (new reporting forms, updated 152-FZ forms, innovations in labor legislation) in order to use the natural surge of interest in fresh templates.

The expert also predicts the expansion of such schemes to messengers and work chats — a link to a form on behalf of a colleague or partner looks more convincing and reliable than a search site. It is also possible to use AI tools to generate better phishing landing pages and texts that mimic official resources or professional communities of accountants or lawyers.

What schemes on the topic of document templates have been found on the Web before

Meanwhile, hackers have tried to use the theme of document templates to deceive users before. In particular, according to Alena Yartseva, there have already been schemes with document templates for financial statements.

— The attackers created fake websites of government departments and legal reference systems - the Bank of Russia discovered this scheme in 2023 and 2024, — says the interlocutor of Izvestia. — And abroad, in 2025, the Goatloader scheme was discovered, in which attackers distributed VPO through websites with free legal templates.

In turn, Security Vision expert Pavel Vinokurov considers malicious macros to be previously popular schemes. Office format files (.docx .xlsx), when opened, the user was prompted to enable macros for correct display. This activated a hidden script downloading the virus. In addition, the attackers used fake updates.

Under the guise of having to update fonts or plug-ins to view the "new GOST document", malicious software was slipped to the user. Finally, hackers exploited vulnerabilities in Microsoft Office or Adobe Reader, allowing them to infect a computer simply by opening a file without any clicks. The main target of such attacks is employees who have access to financial, personnel and legally relevant information of the company, Alexey Mironov notes.

— It is possible to predict the expansion of victim profiles: attacks can also be directed at tender specialists and other employees working with template documentation, — Dmitry Zubarev believes.

The main danger of such tricks, according to Alexey Mironov, is that the attacked employees often work with real personal data, bank details and corporate documents, and the Trojan, once fixed on a work computer or laptop, can be used to steal credentials, intercept correspondence, access to 1C and the client bank, or as an entry point for further distribution across the corporate network.

How to protect yourself from fraud schemes on the subject of document templates

In order to protect themselves from fraud schemes on the subject of document templates, experts interviewed by Izvestia advise following certain security rules. Sergey Polunin, head of the Gazinformservice IT infrastructure Solutions protection group, reminds that the document should be a file in an understandable format like pdf, docx or, for example, xlsx, and not a program.

"There are no documents in exe or msi format, no matter what they are called," the expert warns. — Of course, these documents have their own ways of introducing malicious code, but this is much less common.

When working for a company, most likely, an employee has a tool that filters all attachments in an email or when downloading, and 99% of such malicious files simply will not reach the computer, but this does not mean that vigilance should be forgotten, emphasizes Sergey Polunin.

It is important to download document templates from trusted sources, pay attention to the names of sites and check the presence of an advertising plate in search engines (often malicious sites are the first in the search due to paid promotion), adds Alena Yartseva. It is worth remembering that sometimes it is enough just to visit a malicious website to become infected, so checking downloaded files with an antivirus does not always help secure the device. To ensure security, it is necessary to periodically check the entire system with a security program.

"At the company level, it is important to use an up—to—date antivirus with behavioral analysis, restrict the rights to run executable files from folders like Downloads, and regularly remind employees of the rules for safe handling of files from external sources," concludes Alexey Mironov.

Переведено сервисом «Яндекс Переводчик»

Live broadcast