Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
phishing-campaign-intelligencestate-sponsored-espionagegovernment-diplomatic-threatcredential-access-method

Phishing and Social Engineering Campaigns Leveraging Trusted Channels and China-Linked Tradecraft

Updated 3mo agoFirst seen Feb 6, 20262 sources

Multiple reports highlight social engineering-driven compromise rather than exploitation of software vulnerabilities, with attackers relying on trusted-looking communications and infrastructure to bypass defenses. One campaign described by X-Labs uses a “clean” initial business email (often passing SPF/DKIM/DMARC) that contains no direct malicious link, instead delivering a PDF attachment that leads victims through a multi-stage document chain. The chain leverages reputable cloud services—including Vercel Blob—to host intermediary PDFs that redirect to a Dropbox-impersonation credential-harvesting page, and then uses a Telegram bot as a collection point for stolen credentials, complicating detection and takedown.

Separately, researchers reported a targeted operation attributed to China-linked Mustang Panda (aka HoneyMyte) against government officials and diplomats, using fake diplomatic briefing documents themed as U.S./international policy updates to induce execution and install surveillance tooling, including PlugX (noted as a DOPLUGS variant). In parallel, U.S. reporting described HUMINT-style recruitment approaches tied primarily to China, where adversaries pose as recruiters/consulting firms on email and job platforms to elicit or purchase sensitive information from current/former U.S. government personnel—an espionage pathway that is adjacent to, but distinct from, the phishing/malware activity described in the other reporting.

Share:
Phishing and Social Engineering Campaigns Leveraging Trusted Channels and China-Linked Tradecraft
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Feb 6, 20265mo ago

X-Labs reports cloud-hosted phishing campaign abusing Vercel and Telegram

By 2026-02-06, X-Labs had documented a multi-stage phishing campaign in which procurement-themed emails with PDF attachments led victims through Vercel-hosted content to a Dropbox-impersonation login page. The operation harvested credentials and additional system and location data, then exfiltrated the information via attacker-controlled infrastructure including a Telegram bot or channel.

Jan 15, 20265mo ago

Dream Research Labs detects the Mustang Panda activity

In mid-January 2026, Dream Research Labs detected the campaign after an AI-based hunting agent flagged a suspicious archive. Dream assessed the operation as focused on espionage related to elections and international coordination.

Dec 25, 20256mo ago

Mustang Panda runs fake diplomatic briefing espionage campaign

Between late December 2025 and mid-January 2026, government officials and international diplomats were targeted in an espionage campaign using impersonation and weaponized diplomatic-style briefing documents. The intrusion chain deployed a PlugX (DOPLUGS) downloader variant, used custom encryption and DLL search-order hijacking, and was later attributed by Dream Research Labs to the China-linked Mustang Panda group.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Affected products
3 linked
TelegramDropboxDropbox
Organizations
6 linked
DropboxXVercelTelegramHackread.comDream
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.