Multi-stage phishing and supply-chain malware campaigns targeting credentials and long-term access
Multiple reports highlight active campaigns using phishing and software supply-chain abuse to steal credentials and establish persistence. eSentire described an espionage-focused operation targeting residents of India with emails impersonating the Income Tax Department, leading victims to a malicious archive that uses DLL side-loading with a legitimate signed Microsoft application, extensive anti-analysis checks, in-memory shellcode unpacking, UAC bypass, and process masquerading; the payload was identified as a Blackmoon-family variant that specifically attempts to disable Avast Free Antivirus by automating UI interactions to add exclusions. Separately, Aikido reported a malicious npm package (ansi-universal-ui) that deploys a multi-stage infostealer (“G_Wagon”) by abusing postinstall execution, downloading a Python runtime, running an obfuscated payload, and exfiltrating browser credentials, cloud credentials, Discord tokens, and data from 100+ cryptocurrency wallets to an Appwrite storage bucket; it also includes a Windows DLL used for browser-process injection via NT native APIs.
In parallel, network-edge exploitation remains a key access vector: Risky Business reported a renewed wave of attacks against Fortinet FortiGate devices via a vulnerability Fortinet allegedly “patched” in December but which attackers can still exploit, enabling SSO authentication bypass (via crafted SAML), creation of new admin accounts, and theft of device configuration; mitigations include disabling the FortiCloud SSO feature (not enabled by default). Several other items are general awareness or roundup content rather than specific incident reporting: TechTarget and other blogs emphasized ongoing phishing/email risk (including relay spam abusing legitimate Zendesk instances) and password hygiene, while The Hacker News published a multi-story bulletin that includes (among other items) a spear-phishing campaign in Afghanistan delivering a FALSECUB backdoor via a GitHub-hosted ISO and LNK execution chain; Risky Business also covered Iran’s internet blackout and Starlink jamming/spoofing as a communications-control issue rather than an enterprise cyber incident.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
5 events from the most recent confirmed update back to the earliest known activity.
Aikido detects malicious npm package ansi-universal-ui
On January 23, 2026, Aikido reported the npm package "ansi-universal-ui" as a malicious multi-stage infostealer. The package had rapidly evolved over the prior two days into a weaponized installer that deployed the G_Wagon Python stealer to target browser data, crypto wallets, and cloud credentials.
New attacks exploit improperly patched Fortinet FortiGate bug
By January 2026, a new wave of attacks was exploiting CVE-2025-59718 against Fortinet FortiGate firewalls despite the December patch. Arctic Wolf reported attackers were bypassing SSO with generic usernames, creating new admin accounts for persistence, and stealing device configuration files.
SmarterMail patches exploited admin password reset zero-day
SmarterMail issued a patch on January 15, 2026 for an admin password reset zero-day that had been exploited before the fix became available. The issue was highlighted as one of several actively exploited vulnerabilities in contemporaneous security reporting.
Fortinet patches CVE-2025-59718 SSO flaw in FortiGate firewalls
Fortinet released a patch in December 2025 for CVE-2025-59718, a FortiGate Single Sign-On weakness that allowed attackers to craft malicious SAML messages and gain administrative access without authenticating. Later reporting suggested the fix may have been incomplete in newer firmware.
eSentire reports SyncFuture espionage campaign targeting India
In early December 2025, eSentire's Threat Response Unit identified an active multi-stage espionage campaign targeting residents of India with phishing emails impersonating the Income Tax Department of India. The intrusion used DLL sideloading, anti-analysis techniques, privilege escalation, and ultimately deployed the legitimate SyncFuture TSM product for persistence and data theft.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
3 references tracked. Mallory keeps watching after this page renders.
G_Wagon: npm Package Deploys Python Stealer Targeting 100+ Crypto Wallets
aikido.dev
Open sourceImproperly patched bug exploited again in Fortinet firewalls
news.risky.biz
Open sourceWeaponized in China, Deployed in India: The SyncFuture Espionage Targeted Campaign | eSentire
esentire.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


