Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
defense-evasion-methodloader-delivery-mechanismphishing-campaign-intelligenceremote-access-implant

Malware Campaigns Using Social Engineering to Deliver Proxyware, RATs, and Ransomware

Updated 3mo agoFirst seen Jan 22, 20263 sources

Multiple active malware campaigns are using social engineering and trojanized content to compromise Windows systems, with lures ranging from pirated software downloads to business and shipping documents. AhnLab reported a “proxyjacking” operation attributed to Larva-25012 that distributes fake installers (notably a trojanized Notepad++ package) via cracked-software sites; the Setup.zip bundle includes a legitimate Setup.exe plus a malicious sideloaded DLL (TextShaping.dll) that decrypts and installs DPLoader for persistent command retrieval and follow-on payload delivery. The malware also tampers with defenses by changing Microsoft Defender settings (e.g., exclusions, reduced notifications, and blocking sample submission) to reduce detection while monetizing victims’ bandwidth through installed proxyware.

Separately, FortiGuard Labs described a Russia-focused, multi-stage intrusion chain that abuses trusted services (GitHub and Dropbox) for payload hosting and weaponizes Defendnot (a Windows Security Center trust-model research tool) to disable Microsoft Defender before deploying a ransomware payload. Fortinet also documented phishing campaigns using weaponized shipping-themed Word documents to deliver Remcos RAT, including fileless execution behavior and exploitation of CVE-2017-11882 (Microsoft Equation Editor) via remotely fetched templates. These campaigns reinforce the operational risk from user-driven execution paths (pirated installers and document lures), “living off the land” techniques, and defense evasion through both policy tampering and security tooling abuse.

Share:
Malware Campaigns Using Social Engineering to Deliver Proxyware, RATs, and Ransomware
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jan 22, 20265mo ago

ASEC warns of Larva-25012 fake Notepad++ installer proxyjacking campaign

AhnLab Security Intelligence Center warned that threat actor Larva-25012 is distributing trojanized Notepad++ installers through fake software download sites aimed at users seeking cracked or pirated software. The malware uses DLL side-loading to install DPLoader, weakens Windows Defender, persists via scheduled tasks, and monetizes victims by installing proxyware such as Infatica and DigitalPulse.

FortiGuard reports Russia-focused campaign abusing Defendnot and cloud services

FortiGuard Labs disclosed a multi-stage campaign targeting users in Russia that uses business-themed decoy documents, weaponized Defendnot to disable Microsoft Defender, and payload hosting on GitHub and Dropbox. The intrusion deploys Amnesia RAT and later ransomware and WinLocker components for persistent control, credential theft, and data denial.

Jan 21, 20265mo ago

Fortinet identifies phishing campaign delivering Remcos via shipping lures

Fortinet analysts reported a phishing campaign using fake shipping emails with malicious Word documents that fetch remote templates and exploit CVE-2017-11882 to install Remcos RAT. The attack uses fileless execution, scheduled-task persistence, and TLS command-and-control to evade detection and maintain access on Windows systems.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

25 LINKEDOpen in app
Threat actors
1 linked
Affected products
10 linked
Windows DefenderWindows ExplorerNotepad++PythonNetGithubDropboxGithubDropboxNet
Organizations
7 linked
Microsoft CorporationAhnlabInfaticaDigitalPulseFortinetDropboxGitHub
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.