Malware Campaigns Using Social Engineering to Deliver Proxyware, RATs, and Ransomware
Multiple active malware campaigns are using social engineering and trojanized content to compromise Windows systems, with lures ranging from pirated software downloads to business and shipping documents. AhnLab reported a “proxyjacking” operation attributed to Larva-25012 that distributes fake installers (notably a trojanized Notepad++ package) via cracked-software sites; the Setup.zip bundle includes a legitimate Setup.exe plus a malicious sideloaded DLL (TextShaping.dll) that decrypts and installs DPLoader for persistent command retrieval and follow-on payload delivery. The malware also tampers with defenses by changing Microsoft Defender settings (e.g., exclusions, reduced notifications, and blocking sample submission) to reduce detection while monetizing victims’ bandwidth through installed proxyware.
Separately, FortiGuard Labs described a Russia-focused, multi-stage intrusion chain that abuses trusted services (GitHub and Dropbox) for payload hosting and weaponizes Defendnot (a Windows Security Center trust-model research tool) to disable Microsoft Defender before deploying a ransomware payload. Fortinet also documented phishing campaigns using weaponized shipping-themed Word documents to deliver Remcos RAT, including fileless execution behavior and exploitation of CVE-2017-11882 (Microsoft Equation Editor) via remotely fetched templates. These campaigns reinforce the operational risk from user-driven execution paths (pirated installers and document lures), “living off the land” techniques, and defense evasion through both policy tampering and security tooling abuse.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
3 events from the most recent confirmed update back to the earliest known activity.
ASEC warns of Larva-25012 fake Notepad++ installer proxyjacking campaign
AhnLab Security Intelligence Center warned that threat actor Larva-25012 is distributing trojanized Notepad++ installers through fake software download sites aimed at users seeking cracked or pirated software. The malware uses DLL side-loading to install DPLoader, weakens Windows Defender, persists via scheduled tasks, and monetizes victims by installing proxyware such as Infatica and DigitalPulse.
FortiGuard reports Russia-focused campaign abusing Defendnot and cloud services
FortiGuard Labs disclosed a multi-stage campaign targeting users in Russia that uses business-themed decoy documents, weaponized Defendnot to disable Microsoft Defender, and payload hosting on GitHub and Dropbox. The intrusion deploys Amnesia RAT and later ransomware and WinLocker components for persistent control, credential theft, and data denial.
Fortinet identifies phishing campaign delivering Remcos via shipping lures
Fortinet analysts reported a phishing campaign using fake shipping emails with malicious Word documents that fetch remote templates and exploit CVE-2017-11882 to install Remcos RAT. The attack uses fileless execution, scheduled-task persistence, and TLS command-and-control to evade detection and maintain access on Windows systems.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
3 references tracked. Mallory keeps watching after this page renders.
Bandwidth Bandits: Fake Notepad++ Installers Hide "Proxyjacking" Malware
securityonline.info
Open sourceGitHub & Dropbox Weaponized: "Defendnot" Tool Used to Disable Windows Defender
securityonline.info
Open sourceBeware of Weaponized Shipping Documents that Deliver Remcos RAT with a Wide Range of Capabilities
cybersecuritynews.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


