Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
phishing-campaign-intelligenceremote-access-implantinitial-access-methoddefense-evasion-method

Phishing Campaigns Abuse Trusted Platforms and Tools to Deliver Remote Access Malware

Updated 2mo agoFirst seen Jan 26, 20263 sources

Multiple reports describe phishing-led malware delivery that abuses trusted services and “living off the land” execution paths to evade controls and deploy remote access tooling. Cloudflare-tracked activity shows attackers using Vercel-hosted pages to lend legitimacy to malicious links and bypass email/security filtering, with lures themed around invoices, payments, shipping, and document portals; the infrastructure includes Telegram-based filtering and browser fingerprinting/conditional delivery to hinder researchers and sandboxes before serving payloads that install a remote access tool (RAT).

A separate campaign (tracked as PHALT#BLYX) targets hospitality staff with Booking[.]com-style reservation emails and uses a fake browser error + fake BSOD to coerce victims into running the ClickFix technique (Win+R paste/execute), launching PowerShell that pulls malicious project files and executes them via MSBuild.exe to deliver DCRat, consistent with LOLBins-based evasion; researchers noted Russian-language artifacts in the malware. Broader weekly/newsletter roundups also highlight the same risk theme—attackers increasingly blend social engineering with trusted infrastructure and tools—while mixing in unrelated items (e.g., firewall CVEs, general malware research links) that are not part of a single, specific incident narrative.

Share:
Phishing Campaigns Abuse Trusted Platforms and Tools to Deliver Remote Access Malware
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Apr 15, 20262mo ago

ANY.RUN reports Google Cloud Storage phishing campaign delivering Remcos RAT

In April 2026, ANY.RUN reported a phishing campaign abusing storage.googleapis.com to host fake Google Drive login pages that steal credentials and one-time passcodes before delivering a multi-stage infection chain. The attack used JavaScript, VBS, PowerShell, an in-memory .NET loader from Textbin, and process hollowing via Microsoft-signed RegSvcs.exe to deploy Remcos RAT.

Hackers Using Google Cloud Storage to Bypass Email Filters and Deliver Remcos RAT
Jan 26, 20265mo ago

Cloudflare reports updated Vercel campaign using Telegram filtering

On January 26, 2026, Cloudflare analysts reported that the Vercel-based phishing campaign had evolved from earlier activity, adding Telegram-based filtering to block researchers and sandboxes from reaching the payload. The report also detailed the use of fake document viewers and signed GoTo Resolve binaries to gain full remote control of victim systems.

Researchers detail DCRat delivery and defense evasion in PHALT#BLYX campaign

Analysis published on January 26, 2026 described how the PHALT#BLYX infection chain weakened Windows Defender with broad exclusions, attempted privilege escalation through repeated UAC prompts, and deployed an obfuscated DCRat variant for persistence, reconnaissance, keylogging, and remote access. The report highlighted the campaign's use of living-off-the-land techniques and potential for follow-on actions such as credential theft or ransomware deployment.

PHALT#BLYX targets hospitality firms with fake Booking.com alerts

By January 2026, a campaign tracked as PHALT#BLYX was targeting hospitality businesses with phishing emails posing as Booking.com reservation cancellation notices. Victims were redirected to fake Booking.com pages using fake browser errors, a simulated BSOD, and ClickFix social engineering to launch PowerShell and execute malware via MSBuild.exe.

Nov 1, 20258mo ago

Vercel phishing campaign runs with evolving delivery tactics

Between November 2025 and January 2026, threat actors continued a phishing campaign that abused Vercel's legitimate hosting platform with lures such as invoices, payment statements, shipping documents, and fake document portals. The operation used browser fingerprinting and Telegram-based target validation before delivering a signed copy of GoTo Resolve for remote access.

Jun 1, 20251y ago

CyberArmor first documents Vercel-based phishing campaign

In June 2025, CyberArmor first documented a phishing campaign abusing Vercel-hosted pages to deliver malware and remote access tooling. This established the earlier known activity later analyzed by Cloudflare.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Malware
1 linked
Affected products
3 linked
TelegramWindowsPowershell
Organizations
8 linked
SecuronixCloudflareBooking.comCyberArmorMicrosoft CorporationAdobeVercelLogmein
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Phishing Campaigns Abuse Trusted Platforms and Tools to Deliver Remote Access Malware | Mallory