Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligencepackage-repository-poisoningcredential-stealer-activityidentity-authentication-vulnerability

Multi-stage phishing and supply-chain malware campaigns targeting credentials and long-term access

Updated 3mo agoFirst seen Jan 23, 20263 sources

Multiple reports highlight active campaigns using phishing and software supply-chain abuse to steal credentials and establish persistence. eSentire described an espionage-focused operation targeting residents of India with emails impersonating the Income Tax Department, leading victims to a malicious archive that uses DLL side-loading with a legitimate signed Microsoft application, extensive anti-analysis checks, in-memory shellcode unpacking, UAC bypass, and process masquerading; the payload was identified as a Blackmoon-family variant that specifically attempts to disable Avast Free Antivirus by automating UI interactions to add exclusions. Separately, Aikido reported a malicious npm package (ansi-universal-ui) that deploys a multi-stage infostealer (“G_Wagon”) by abusing postinstall execution, downloading a Python runtime, running an obfuscated payload, and exfiltrating browser credentials, cloud credentials, Discord tokens, and data from 100+ cryptocurrency wallets to an Appwrite storage bucket; it also includes a Windows DLL used for browser-process injection via NT native APIs.

In parallel, network-edge exploitation remains a key access vector: Risky Business reported a renewed wave of attacks against Fortinet FortiGate devices via a vulnerability Fortinet allegedly “patched” in December but which attackers can still exploit, enabling SSO authentication bypass (via crafted SAML), creation of new admin accounts, and theft of device configuration; mitigations include disabling the FortiCloud SSO feature (not enabled by default). Several other items are general awareness or roundup content rather than specific incident reporting: TechTarget and other blogs emphasized ongoing phishing/email risk (including relay spam abusing legitimate Zendesk instances) and password hygiene, while The Hacker News published a multi-story bulletin that includes (among other items) a spear-phishing campaign in Afghanistan delivering a FALSECUB backdoor via a GitHub-hosted ISO and LNK execution chain; Risky Business also covered Iran’s internet blackout and Starlink jamming/spoofing as a communications-control issue rather than an enterprise cyber incident.

Share:
Multi-stage phishing and supply-chain malware campaigns targeting credentials and long-term access
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jan 23, 20265mo ago

Aikido detects malicious npm package ansi-universal-ui

On January 23, 2026, Aikido reported the npm package "ansi-universal-ui" as a malicious multi-stage infostealer. The package had rapidly evolved over the prior two days into a weaponized installer that deployed the G_Wagon Python stealer to target browser data, crypto wallets, and cloud credentials.

Jan 22, 20265mo ago

New attacks exploit improperly patched Fortinet FortiGate bug

By January 2026, a new wave of attacks was exploiting CVE-2025-59718 against Fortinet FortiGate firewalls despite the December patch. Arctic Wolf reported attackers were bypassing SSO with generic usernames, creating new admin accounts for persistence, and stealing device configuration files.

Jan 15, 20265mo ago

SmarterMail patches exploited admin password reset zero-day

SmarterMail issued a patch on January 15, 2026 for an admin password reset zero-day that had been exploited before the fix became available. The issue was highlighted as one of several actively exploited vulnerabilities in contemporaneous security reporting.

Dec 1, 20257mo ago

Fortinet patches CVE-2025-59718 SSO flaw in FortiGate firewalls

Fortinet released a patch in December 2025 for CVE-2025-59718, a FortiGate Single Sign-On weakness that allowed attackers to craft malicious SAML messages and gain administrative access without authenticating. Later reporting suggested the fix may have been incomplete in newer firmware.

eSentire reports SyncFuture espionage campaign targeting India

In early December 2025, eSentire's Threat Response Unit identified an active multi-stage espionage campaign targeting residents of India with phishing emails impersonating the Income Tax Department of India. The intrusion used DLL sideloading, anti-analysis techniques, privilege escalation, and ultimately deployed the legitimate SyncFuture TSM product for persistence and data theft.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

114 LINKEDOpen in app
Affected products
25 linked
TelegramDiscordAppwriteMetamaskBrave BrowserSteamLedger LiveSteamMetamaskSmartermailInno SetupGitlabFortigateSignalSendgridZoomOpensslUnified Communications ManagerFirefoxActive DirectoryAvast Free AntivirusZendeskSendgridOpensslGitlab
Organizations
67 linked
BroadcomMozillaAkamai TechnologiesCheck Point Software TechnologiesArctic WolfCisco SystemsGreyNoiseZendeskDLA PiperF6AtlassianGlobalSignCensysSocketKELATenableSpecterOpsGitLabLastPassPromptArmoreSentireAnthropicPicus SecurityZoom CommunicationsRecorded FutureNSO GroupXiaomiMeta PlatformsPenteraBlack KiteFortinetOpenaiExpelSansecHarmonic SecurityCellebriteXMicrosoft CorporationCyberarkOracleVulnCheckWatchTowrGroup-IBSignal MessengerEllipticRSA ConferenceRostelecomVivotekZafran SecurityAbstract SecurityPermiso SecurityAbnormal AIPoint WildCyataGoogleManage My HealthAvast Software s.r.o.Twilio SendGridCyber CentaursCenter for Countering Digital HateSagaEVMUStriveSwiss PostW SocialSyncFutureTec Company LimitedNanjing Yangtu Information Technology Co., Ltd.Nanjing Zhongke Huasai Technology Co., Ltd
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.