Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
loader-delivery-mechanismphishing-campaign-intelligenceremote-access-implantendpoint-security-bypass

Malware Delivery via Social Engineering: Phishing Lures, Fake Browser Alerts, and Paste-and-Run Payloads

Updated 3mo agoFirst seen Jan 25, 20264 sources

Multiple threat reports describe social-engineering-driven malware delivery leading to remote access and follow-on payload deployment. Fortinet observed a multi-stage phishing campaign targeting users in Russia that delivers Amnesia RAT and ransomware via business-themed decoy documents and a malicious .lnk shortcut using a double extension (e.g., *.txt.lnk). The infection chain uses public cloud services for staging—GitHub for scripts and Dropbox for binary payloads—and abuses defendnot to trick Windows into believing a third-party AV is installed, effectively disabling Microsoft Defender before later-stage execution.

Separately, Huntress attributed activity to KongTuke, which uses malicious browser extensions to display fake “browser crash” security alerts (“CrashFix”) that pressure users into running attacker-provided commands, and also deploys a Python RAT dubbed ModeloRAT. ModeloRAT is described as heavily obfuscated, using Windows Registry persistence and RC4-encrypted communications, with the ability to deliver additional payloads (DLLs, executables, scripts). Red Canary’s January intelligence update highlights Scarlet Goldfinch activity using paste-and-run lures and a notable technique of using the Windows finger client to pull remote content (e.g., finger user@IP | cmd), followed by curl download of an archive masquerading as a PDF and extraction via tar -xf, culminating in Remcos (and sometimes NetSupport) delivered via DLL sideloading.

Share:
Malware Delivery via Social Engineering: Phishing Lures, Fake Browser Alerts, and Paste-and-Run Payloads
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jan 25, 20265mo ago

Rescana links Russia campaign TTPs to DupeHike and Paper Werewolf

A follow-up analysis assessed the phishing activity as sophisticated and noted overlaps in tactics, techniques, and procedures with UNG0902's Operation DupeHike and Paper Werewolf/GOFFEE. The report suggested a well-resourced actor pursuing a mix of espionage and financial objectives.

Jan 24, 20265mo ago

Microsoft issues mitigation guidance for defendnot-style abuse

In response to the observed tradecraft, Microsoft recommended enabling Tamper Protection and monitoring for suspicious use of Windows Security Center APIs. The guidance was aimed at detecting and mitigating attempts to disable Defender through fake antivirus registration.

Campaign deploys Amnesia RAT, ransomware, and WinLocker

Researchers reported that the same intrusion chain delivered Amnesia RAT for credential theft, surveillance, and remote control, followed by a Hakuna Matata-family ransomware variant that encrypted files and monitored the clipboard for cryptocurrency wallet swapping. The attack concluded with WinLocker to restrict user interaction on compromised systems.

Researchers detail defendnot abuse to disable Microsoft Defender

Analysis of the Russia-focused phishing campaign revealed the attackers used the public tool defendnot to register a fake antivirus with Windows Security Center, causing Microsoft Defender to turn off. The campaign also added Defender exclusions and tampered with policy and registry settings to reduce visibility and recovery options.

Fortinet reports phishing campaign hitting Russian organizations

Fortinet FortiGuard Labs reported a multi-stage phishing campaign targeting users in Russia with business-themed decoys and malicious LNK files in archives. The campaign delivered Amnesia RAT and a Hakuna Matata-derived ransomware without exploiting software vulnerabilities, instead abusing native Windows features and public services like GitHub, Dropbox, and Telegram.

Dec 1, 20257mo ago

Remcos intrusion chain uses Finger, curl, tar, and DLL sideloading

During the December 2025 activity, Red Canary observed an intrusion chain beginning with paste-and-run lures and use of the Windows Finger utility to retrieve remote commands or payloads. Follow-on stages used curl to download a PDF-disguised archive, tar to extract it, and DLL sideloading through a legitimate vulnerable executable to launch a malicious Remcos DLL.

Red Canary observes Remcos rise in Scarlet Goldfinch activity

In December 2025, Red Canary observed Remcos enter its top 10 payloads associated with the Scarlet Goldfinch activity cluster. The malware was seen delivered both alongside NetSupport Manager and on its own, suggesting a possible shift in tooling.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

52 LINKEDOpen in app
Affected products
18 linked
MetamaskGithubYandex BrowserDiscordBrave BrowserOpera BrowserTelegram DesktopDropboxGithubDropboxSteamChromiumChromiumChromiumChromiumMetamaskWindowsQuick Share
Organizations
26 linked
Valve CorporationElectrum Technologies GmbHDiscordEthereumBrave SoftwareDropboxYandexMicrosoft CorporationGitHubTelegramMetamaskJaxxCoinomiAtomic WalletZ.CashVivaldi TechnologiesGuardaRescanaGoogleGoFileArmory Technologies, Inc.BytecoinExodus MovementOpera NorwayRed CanaryBreaking Security
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.