Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
initial-access-methoddefense-evasion-methodphishing-campaign-intelligenceremote-access-implant

Stealthy Malware Campaigns Abuse Windows and Office Features for Initial Access and Evasion

Updated 2mo agoFirst seen Feb 6, 20264 sources

Multiple early-2026 campaigns highlight increasingly low-noise initial access and living-off-the-land execution on Windows endpoints. CyStack reported activity attributed to APT-Q-27 (GoldenEyeDog) targeting financial institutions via a corporate support workflow: a user clicked a malicious link delivered through a Zendesk ticket, leading to download of an executable masquerading as an image/.pif file (aided by Windows’ hidden-extension defaults). The malware was signed with a revoked certificate that still appeared trusted due to a valid timestamp, and its modular backdoor/C2 infrastructure overlapped with prior APT-Q-27 activity, enabling stealthy persistence and control without triggering common endpoint alerts.

Separately, Securonix described the Dead#Vax multistage campaign using phishing links to VHD files hosted on IPFS, where mounting/opening the VHD triggers Windows Script Files, obfuscated batch, and PowerShell loaders to support encrypted data theft and conceal execution logic, culminating in AsyncRAT deployment for credential theft, surveillance, and follow-on intrusion. In another targeted operation, Zscaler ThreatLabz linked Operation Neusploit to APT28, exploiting CVE-2026-21509 (Microsoft Office/365 OLE bypass) via crafted RTF documents to drop payloads including MiniDoor (Outlook-focused collection and mailbox manipulation, including exfiltration to attacker-controlled email accounts) and PixyNetLoader (reported to use steganography). A separate “ThreatsDay” bulletin is a multi-story roundup and does not provide additional, specific corroboration on these same campaigns beyond mentioning adjacent themes (e.g., AsyncRAT/C2) in a broader news digest.

Share:
Stealthy Malware Campaigns Abuse Windows and Office Features for Initial Access and Evasion
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Feb 6, 20265mo ago

APT-Q-27 targeting corporate environments is reported

A report published on 6 February 2026 stated that APT-Q-27 was conducting stealthy attacks against corporate environments designed to avoid triggering alerts. No further technical or chronological details were provided in the reference synopsis.

Securonix discloses Dead#Vax multistage malware campaign

Securonix analysts reported a sophisticated Windows-focused campaign dubbed Dead#Vax that used phishing emails, IPFS-hosted VHD files, Windows Script Files, batch scripts, and PowerShell loaders. The intrusion chain culminated in AsyncRAT deployment for credential theft, surveillance, data exfiltration, and follow-on compromise.

Feb 1, 20265mo ago

Lab52 reports phishing campaign abusing renamed MSBuild and .csproj files

In February 2026, a campaign reported by Lab52 used phishing emails to deliver a renamed MSBuild executable and a malicious .csproj project file, causing MSBuild to load the project, fetch additional payloads from external infrastructure, and execute them. The intrusion chain also used DLL sideloading with a legitimate signed executable and a malicious DLL to achieve final malware execution.

LOLBins - Analyzing attack techniques with MSBuild - ASEC
Jan 29, 20265mo ago

Operation Neusploit exploitation continues after patch release

Zscaler observed exploitation of CVE-2026-21509 continuing through at least 29 January 2026 despite Microsoft's emergency patch. The campaign's second-stage activity included steganography, anti-analysis checks, and deployment of a Covenant Grunt implant using Filen for command-and-control and data movement.

Zscaler uncovers Operation Neusploit targeting Eastern Europe

Zscaler ThreatLabz identified a targeted campaign dubbed Operation Neusploit in January 2026 aimed at users in Ukraine, Slovakia, and Romania. The operation used localized lure documents and malicious RTF files to exploit CVE-2026-21509 and deliver malware including MiniDoor and PixyNetLoader.

Jan 26, 20265mo ago

Microsoft issues emergency patch for CVE-2026-21509

Microsoft released an emergency patch for the critical Microsoft Office/365 OLE vulnerability CVE-2026-21509, which could be triggered by opening a crafted file. The flaw was later linked to targeted malware attacks in Operation Neusploit.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

16 LINKEDOpen in app
Threat actors
1 linked
Affected products
2 linked
WindowsMicrosoft Office
Organizations
7 linked
Microsoft CorporationAhnlabZscalerSecuronixProtonSilicon AngleFilen
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.