Malware Delivery via Deceptive Lures: Malvertising, Fake Recruitment Repos, and Phishing Dropping RATs
Multiple reports detail social-engineering-driven malware delivery that results in remote access trojans (RATs) and credential theft. Infoblox described observing an affiliate push-notification ad network after exploiting misconfigured DNS delegations (“Sitting Ducks”/lame name server delegation) to take over abandoned threat-actor domains, allowing collection of ~57M logs over two weeks and visibility into widespread scams and brand impersonation delivered via push ads. Nextron Systems separately reported recurring malvertising chains where “free converter” tools (e.g., document/image converters) downloaded from ads on legitimate sites function as advertised while covertly installing persistent RATs, with common artifacts such as Windows Mark-of-the-Web (ZoneId=3) indicating internet origin.
Other activity in the set reflects different initial-access lures but the same general outcome—RAT-style access and data theft. Fortinet analyzed a phishing campaign using a fake Vietnam shipping document: a Word attachment leads to an RTF stage that exploits an RTF-related vulnerability, then uses VBScript/PowerShell to load a fileless .NET module, ultimately downloading and injecting a Remcos variant (including process hollowing) to provide full remote control. Separately, reporting on North Korea’s “Contagious Interview” campaign described fake recruiter outreach (e.g., via LinkedIn) that tricks developers into opening malicious code repositories; execution can be triggered via a hidden VS Code tasks configuration, server-side logic hooks, or a malicious npm dependency to steal credentials/crypto wallets and establish persistence—this is thematically similar (social engineering leading to remote access) but is a distinct operation from the malvertising/push-ad and Remcos phishing activity.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
4 events from the most recent confirmed update back to the earliest known activity.
Infoblox publishes analysis of a malicious push network from 57M logs
Infoblox released a threat intelligence report examining a malicious push network using analysis of 57 million logs. The available reference does not provide further event details beyond the publication of the research.
Detection guidance and indicators released for converter malware campaign
Nextron Systems released defensive guidance focused on monitoring scheduled task creation and execution, relevant Windows and Sysmon events, and using AppLocker or WDAC to block execution from user-writable paths. The publication also shared related delivery domains, code-signing certificate details, and file hashes tied to the campaign.
Researchers detail ConvertMate infection chain and persistence method
Nextron Systems published technical analysis of a representative sample, ConvertMate.exe, showing it installs under %LocalAppData%, creates a victim identifier file, and uses PowerShell to register a scheduled task that launches a second-stage backdoor with delayed recurring execution. The report also described the backdoor's communication with confetly[.]com to authenticate, fetch .NET payloads, and return execution results.
Malvertising campaigns distribute trojanized file-converter software
By mid-January 2026, researchers documented multiple active infection chains in which malicious Google ads and converter-themed websites tricked users into downloading fake or trojanized file-converter tools. The software appeared to work normally while covertly installing persistent remote access malware.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


