Malware Delivery via Social Engineering: Phishing Lures, Fake Browser Alerts, and Paste-and-Run Payloads
Multiple threat reports describe social-engineering-driven malware delivery leading to remote access and follow-on payload deployment. Fortinet observed a multi-stage phishing campaign targeting users in Russia that delivers Amnesia RAT and ransomware via business-themed decoy documents and a malicious .lnk shortcut using a double extension (e.g., *.txt.lnk). The infection chain uses public cloud services for staging—GitHub for scripts and Dropbox for binary payloads—and abuses defendnot to trick Windows into believing a third-party AV is installed, effectively disabling Microsoft Defender before later-stage execution.
Separately, Huntress attributed activity to KongTuke, which uses malicious browser extensions to display fake “browser crash” security alerts (“CrashFix”) that pressure users into running attacker-provided commands, and also deploys a Python RAT dubbed ModeloRAT. ModeloRAT is described as heavily obfuscated, using Windows Registry persistence and RC4-encrypted communications, with the ability to deliver additional payloads (DLLs, executables, scripts). Red Canary’s January intelligence update highlights Scarlet Goldfinch activity using paste-and-run lures and a notable technique of using the Windows finger client to pull remote content (e.g., finger user@IP | cmd), followed by curl download of an archive masquerading as a PDF and extraction via tar -xf, culminating in Remcos (and sometimes NetSupport) delivered via DLL sideloading.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
7 events from the most recent confirmed update back to the earliest known activity.
Rescana links Russia campaign TTPs to DupeHike and Paper Werewolf
A follow-up analysis assessed the phishing activity as sophisticated and noted overlaps in tactics, techniques, and procedures with UNG0902's Operation DupeHike and Paper Werewolf/GOFFEE. The report suggested a well-resourced actor pursuing a mix of espionage and financial objectives.
Microsoft issues mitigation guidance for defendnot-style abuse
In response to the observed tradecraft, Microsoft recommended enabling Tamper Protection and monitoring for suspicious use of Windows Security Center APIs. The guidance was aimed at detecting and mitigating attempts to disable Defender through fake antivirus registration.
Campaign deploys Amnesia RAT, ransomware, and WinLocker
Researchers reported that the same intrusion chain delivered Amnesia RAT for credential theft, surveillance, and remote control, followed by a Hakuna Matata-family ransomware variant that encrypted files and monitored the clipboard for cryptocurrency wallet swapping. The attack concluded with WinLocker to restrict user interaction on compromised systems.
Researchers detail defendnot abuse to disable Microsoft Defender
Analysis of the Russia-focused phishing campaign revealed the attackers used the public tool defendnot to register a fake antivirus with Windows Security Center, causing Microsoft Defender to turn off. The campaign also added Defender exclusions and tampered with policy and registry settings to reduce visibility and recovery options.
Fortinet reports phishing campaign hitting Russian organizations
Fortinet FortiGuard Labs reported a multi-stage phishing campaign targeting users in Russia with business-themed decoys and malicious LNK files in archives. The campaign delivered Amnesia RAT and a Hakuna Matata-derived ransomware without exploiting software vulnerabilities, instead abusing native Windows features and public services like GitHub, Dropbox, and Telegram.
Remcos intrusion chain uses Finger, curl, tar, and DLL sideloading
During the December 2025 activity, Red Canary observed an intrusion chain beginning with paste-and-run lures and use of the Windows Finger utility to retrieve remote commands or payloads. Follow-on stages used curl to download a PDF-disguised archive, tar to extract it, and DLL sideloading through a legitimate vulnerable executable to launch a malicious Remcos DLL.
Red Canary observes Remcos rise in Scarlet Goldfinch activity
In December 2025, Red Canary observed Remcos enter its top 10 payloads associated with the Scarlet Goldfinch activity cluster. The malware was seen delivered both alongside NetSupport Manager and on its own, suggesting a possible shift in tooling.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
4 references tracked. Mallory keeps watching after this page renders.
Sophisticated Multi-Stage Phishing Attack Exploits Microsoft Windows in Russian Organizations Using Amnesia RAT and Hakuna Matata Ransomware
rescana.com
Open sourceMulti-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware
thehackernews.com
Open sourceProtection Bulletins
broadcom.com
Open sourceIntelligence Insights: January 2026 | Red Canary
redcanary.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


