Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
remote-access-implantinitial-access-methodphishing-campaign-intelligencecredential-stealer-activity

Malware Delivery via Deceptive Lures: Malvertising, Fake Recruitment Repos, and Phishing Dropping RATs

Updated 3mo agoFirst seen Jan 15, 20262 sources

Multiple reports detail social-engineering-driven malware delivery that results in remote access trojans (RATs) and credential theft. Infoblox described observing an affiliate push-notification ad network after exploiting misconfigured DNS delegations (“Sitting Ducks”/lame name server delegation) to take over abandoned threat-actor domains, allowing collection of ~57M logs over two weeks and visibility into widespread scams and brand impersonation delivered via push ads. Nextron Systems separately reported recurring malvertising chains where “free converter” tools (e.g., document/image converters) downloaded from ads on legitimate sites function as advertised while covertly installing persistent RATs, with common artifacts such as Windows Mark-of-the-Web (ZoneId=3) indicating internet origin.

Other activity in the set reflects different initial-access lures but the same general outcome—RAT-style access and data theft. Fortinet analyzed a phishing campaign using a fake Vietnam shipping document: a Word attachment leads to an RTF stage that exploits an RTF-related vulnerability, then uses VBScript/PowerShell to load a fileless .NET module, ultimately downloading and injecting a Remcos variant (including process hollowing) to provide full remote control. Separately, reporting on North Korea’s “Contagious Interview” campaign described fake recruiter outreach (e.g., via LinkedIn) that tricks developers into opening malicious code repositories; execution can be triggered via a hidden VS Code tasks configuration, server-side logic hooks, or a malicious npm dependency to steal credentials/crypto wallets and establish persistence—this is thematically similar (social engineering leading to remote access) but is a distinct operation from the malvertising/push-ad and Remcos phishing activity.

Share:
Malware Delivery via Deceptive Lures: Malvertising, Fake Recruitment Repos, and Phishing Dropping RATs
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jan 15, 20265mo ago

Infoblox publishes analysis of a malicious push network from 57M logs

Infoblox released a threat intelligence report examining a malicious push network using analysis of 57 million logs. The available reference does not provide further event details beyond the publication of the research.

Jan 14, 20265mo ago

Detection guidance and indicators released for converter malware campaign

Nextron Systems released defensive guidance focused on monitoring scheduled task creation and execution, relevant Windows and Sysmon events, and using AppLocker or WDAC to block execution from user-writable paths. The publication also shared related delivery domains, code-signing certificate details, and file hashes tied to the campaign.

Researchers detail ConvertMate infection chain and persistence method

Nextron Systems published technical analysis of a representative sample, ConvertMate.exe, showing it installs under %LocalAppData%, creates a victim identifier file, and uses PowerShell to register a scheduled task that launches a second-stage backdoor with delayed recurring execution. The report also described the backdoor's communication with confetly[.]com to authenticate, fetch .NET payloads, and return execution results.

Malvertising campaigns distribute trojanized file-converter software

By mid-January 2026, researchers documented multiple active infection chains in which malicious Google ads and converter-themed websites tricked users into downloading fake or trojanized file-converter tools. The software appeared to work normally while covertly installing persistent remote access malware.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
Affected products
2 linked
WindowsPowershell
Organizations
3 linked
THORGoogleDoubleClick
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.