Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
initial-access-methodphishing-campaign-intelligenceremote-access-implantcredential-stealer-activity

Inbound Social Engineering and Malware Delivery Campaigns Targeting Crypto, Web3, and Enterprises

Updated 2mo agoFirst seen Jan 12, 20265 sources

Multiple reports describe social-engineering-led initial access that pivots into malware execution and credential/financial theft. A documented “pig butchering” approach abuses the higher-trust dynamics of matrimonial platforms to build rapport and then steer victims toward cryptocurrency-related actions. Separately, an “inbound” recruitment lure targets Web3/crypto professionals by impersonating legitimate companies and driving candidates to install fake interview software (e.g., collaborex_setup.msi) that initiates command-and-control to infrastructure such as 179.43.159.106, with the added risk that victims often use corporate endpoints that also have personal wallets installed.

In parallel, technical reporting highlights enterprise-focused malware delivery via trojanized software and email. ValleyRAT_S2 (a C++ second-stage backdoor/RAT) is being distributed via fake Chinese-language productivity tools, cracked software, and trojanized installers, including DLL side-loading (e.g., a malicious steam_api64.dll) and C2 over custom TCP (e.g., 27.124.3.175:14852), enabling long-term control and theft of financial data. Kaspersky also reported a malicious-email wave against Russian private-sector organizations using a PDF-icon masquerade that drops a .NET downloader, installs a persistent service, and stages payloads under C:\ProgramData\Microsoft Diagnostic\Tasks before delivering an infostealer. A separate blog post discusses phishing enabled by misconfigured Microsoft 365/hybrid Exchange mail routing and weak SPF/DKIM/DMARC enforcement, allowing spoofed “internal” emails that can facilitate credential theft and BEC; while related in theme (phishing), it is not clearly tied to the same malware campaigns described elsewhere.

Share:
Inbound Social Engineering and Malware Delivery Campaigns Targeting Crypto, Web3, and Enterprises
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Apr 12, 20262mo ago

Fake Web3 job sites used in inverted recruitment scam

An article described an 'inbound' social-engineering tactic in which threat actors allegedly create fake or cloned Web3 companies and post attractive job openings to lure applicants. The report specifically referenced youbuidl.dev as part of this recruitment-themed deception targeting the Web3 and cryptocurrency sectors.

Deception Scenario How Inverted Social Engineering is Redefining the Web3 Recruitment Trap | by Aris Haryanto | InfoSec Write-ups
Jan 12, 20265mo ago

ValleyRAT_S2 campaign uses fake software and side-loading to steal financial data

Researchers reported a campaign distributing the ValleyRAT_S2 second-stage payload through fake Chinese-language productivity tools, cracked software, trojanized installers, spearphishing attachments, and abused update channels. The malware used DLL side-loading, persistence via Temp/AppData files and scheduled tasks, watchdog scripts, and process injection to maintain covert access and collect financial information from victims.

Malicious email campaign targets Russian private-sector organizations

A wave of phishing emails began targeting Russian private-sector organizations with attachments disguised as PDFs that were actually .NET downloader executables. The campaign used a multi-stage infection chain to install a loader, establish persistence as a Windows service, and deploy an infostealer that stole system details, screenshots, and documents for exfiltration.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Affected products
6 linked
WindowsWhatsappSteam.Net FrameworkWindows Script HostSteam
Organizations
4 linked
LinkedinXGoogleMedium
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Inbound Social Engineering and Malware Delivery Campaigns Targeting Crypto, Web3, and Enterprises | Mallory