Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligenceinitial-access-methodremote-access-implantidentity-impersonation-fraud

Social Engineering and Phishing-Driven Intrusions Targeting Identity and Remote Access

Updated 3mo agoFirst seen Jan 20, 20265 sources

Multiple reports highlight social engineering and phishing as primary initial-access vectors, with attackers increasingly targeting identity systems rather than exploiting software vulnerabilities. Microsoft was again the most spoofed brand in phishing during Q4 2025 (22% of observed brand-impersonation attempts), reflecting how attackers abuse trust in major identity and productivity platforms to harvest credentials; examples cited include lures mimicking Netflix account recovery, Roblox-related pages, and Spanish-language Facebook scams. Separately, an incident response case described payroll fraud achieved without malware or a network breach: an attacker impersonated employees to help desks, reset passwords, re-enrolled MFA, and registered an external email as an authentication method in Azure Active Directory, then altered direct-deposit details to redirect paychecks—underscoring how help-desk processes and MFA reset workflows can be exploited for persistence and financial theft.

Targeted campaigns also show continued evolution in delivery tradecraft for remote access. A spear-phishing operation against Argentina’s judicial sector used ZIP attachments containing a weaponized Windows shortcut (.lnk) masquerading as a PDF plus scripts and a decoy court document to deploy a Remote Access Trojan while minimizing user suspicion. In parallel, research described Pulsar RAT (a Quasar RAT derivative) emphasizing stealth via memory-only execution and HVNC, with TLS-encrypted C2 and configuration retrieval from public paste sites, alongside persistence mechanisms such as scheduled tasks and UAC-bypass techniques. Another campaign attributed to Konni APT (“Operation Poseidon”) abused Google and Naver ad redirection (e.g., ad.doubleclick[.]net, mkt.naver[.]com) to launder clicks through trusted ad infrastructure before landing victims on compromised sites hosting malware, demonstrating how open-redirect and ad-tech trust can bypass reputation-based controls.

Share:
Social Engineering and Phishing-Driven Intrusions Targeting Identity and Remote Access
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jan 20, 20265mo ago

Seqrite identifies spear-phishing campaign targeting Argentina's judicial sector

Seqrite reported a targeted phishing operation impersonating Argentine federal court communications to infect judicial-sector victims with a Rust-based RAT. The campaign used ZIP archives containing a malicious LNK, batch loader, decoy legal document, and a multi-stage downloader retrieving payloads from GitHub-hosted infrastructure.

Genians publishes Operation Poseidon report attributing campaign to Konni

Genians Security Center released a report on "Operation Poseidon," describing a campaign that abused Google and Naver ad-click redirection infrastructure to deliver malware through attacker-controlled sites. The researchers attributed the operation to Konni based on an EndRAT build-path artifact containing "Poseidon" and reused command-and-control infrastructure.

Jan 19, 20265mo ago

Investigation finds attacker persisted through Azure AD auth method changes

The payroll-fraud investigation determined the attacker had reset employee passwords, re-enrolled MFA devices, and added an external email address as an authentication method in Azure Active Directory. The activity blended in because the actor used legitimate credentials and valid MFA, and the incident was ultimately contained to three employee accounts.

Payroll diversion fraud discovered after employees report missing pay

An organization uncovered a payroll-diversion scheme after employees reported missing salary deposits. Investigators found the attacker had socially engineered help desk, payroll, IT, and HR processes to change direct-deposit details and reroute paychecks without breaching internal systems.

Oct 1, 20259mo ago

Microsoft ranked most spoofed brand in Q4 2025 phishing attacks

In Q4 2025, Microsoft accounted for 22% of observed brand-impersonation phishing attacks, making it the most spoofed brand in the reporting period. Google, Amazon, Apple, and DHL were also frequently impersonated, with the technology sector remaining the primary target set.

Jan 1, 20251y ago

Malicious npm packages distribute Pulsar RAT in 2025 supply-chain campaign

A 2025 supply-chain campaign used malicious npm packages including "soldiers" and "@mediawave/lib" to distribute Pulsar RAT with multi-layer obfuscation and steganography. The activity was also linked to multi-RAT deployments via open directories alongside Quasar, NjRAT, and XWorm.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

20 LINKEDOpen in app
Affected products
4 linked
WindowsGithubPowershellGithub
Organizations
11 linked
Microsoft CorporationAmazon Web ServicesNetflixMeta PlatformsAppleDHLRobloxGoogleTechRadarSeqriteGitHub
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.