Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
loader-delivery-mechanismphishing-campaign-intelligencedefense-evasion-methodcommand-and-control-method

Multiple Malware Campaigns Abuse Phishing and Legitimate Cloud Services to Compromise Windows and Linux Systems

Updated 3mo agoFirst seen Feb 20, 20265 sources

Reporting describes several unrelated but contemporaneous malware operations targeting both Windows and Linux environments. In Taiwan, FortiGuard Labs observed targeted phishing using tax and e-invoice lures to deliver Winos 4.0 (ValleyRat) and plugins, with delivery chains including malicious .LNK files, DLL sideloading, and BYOVD using the vulnerable driver wsftprm.sys, supported by rapidly rotating domains and cloud-hosted infrastructure that reduces the effectiveness of static blocklists. Separately, Cato CTRL reported a new Windows loader, Foxveil, that stages and retrieves shellcode via trusted platforms (Cloudflare Pages, Netlify, and Discord attachments) and executes payloads using techniques including Early Bird APC injection (often into a fake svchost.exe) or self-injection, while persisting via Windows services or masqueraded binaries dropped into SysWOW64.

Additional reporting covers distinct campaigns in other regions and platforms. A LATAM-focused intrusion chain uses fake bank receipt lures (double-extension such as .pdf.js) to deliver XWorm v5.6, employing oversized/obfuscated JavaScript, WMI-based process creation (Win32_Process) to launch hidden PowerShell, and abuse of a hardcoded Cloudinary URL for staging—capabilities consistent with credential theft and enabling follow-on ransomware. Trellix analysis described a separate Monero cryptomining operation distributed via pirated software installers that propagates through USB/external drives to reach even air-gapped systems, using multi-component “watchdog” self-healing behavior and aggressive defense-evasion. On Linux, LevelBlue detailed a new SysUpdate variant (packed ELF64) that performs host reconnaissance and uses strong C2 encryption; researchers built a Unicorn Engine-based emulation tool to reproduce key generation/encryption routines and decrypt captured C2 traffic for investigation and detection engineering.

Share:
Multiple Malware Campaigns Abuse Phishing and Legitimate Cloud Services to Compromise Windows and Linux Systems
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Feb 20, 20264mo ago

FortiGuard attributes Taiwan Winos activity to Silver Fox subgroup

FortiGuard attributed the Taiwan-focused Winos 4.0 campaigns with high confidence to a specialized subgroup within the Silver Fox APT. The attribution was based on overlapping infrastructure, identical driver-abuse techniques, domain registration artifacts, and a recurring development MachineID.

FortiGuard reports Winos 4.0 phishing campaigns targeting Taiwan

FortiGuard Labs disclosed targeted phishing campaigns in Taiwan using tax-themed lures to deliver Winos 4.0 (ValleyRat) and follow-on plugins. The campaigns use rotating domains, cloud-hosted archives, DLL sideloading, UAC bypass, and a vulnerable driver to disable security products and run memory-resident modules.

Feb 19, 20264mo ago

Researchers disclose advanced air-gap-bridging cryptomining malware

Trellix publicly described the cryptomining campaign's controller/payload separation, BYOVD privilege escalation, and CPU register tampering to improve Monero RandomX mining performance by an estimated 15–50%. The report also highlighted its ability to spread through removable media and bridge air-gapped systems.

XWorm campaign targets Latin American businesses with fake receipts

Researchers reported a multi-stage campaign targeting Brazilian and broader Latin American businesses with fake Bradesco bank receipt lures delivering XWorm v5.6. The infection chain uses a .pdf.js dropper, Cloudinary-hosted steganographic content, in-memory .NET loading, scheduled-task persistence, and CasPol.exe injection.

Feb 18, 20264mo ago

Researchers develop tool to decrypt SysUpdate Linux C2 traffic

To analyze the new SysUpdate variant, researchers built a Unicorn Engine-based emulation toolchain that reproduces the malware's key generation and decryption routines. The method enables defenders to decrypt intercepted C2 traffic from this and future variants by extracting updated keys from memory.

LevelBlue discovers new Linux SysUpdate variant

During a DFIR engagement, analysts found a suspicious packed ELF64 binary in a client environment and attributed it with high confidence to a new Linux-targeting SysUpdate variant. The malware masquerades as a system service, performs reconnaissance, and establishes encrypted multi-protocol C2 communications.

Researchers report Foxveil and its two variants

Security researchers publicly reported the newly discovered Foxveil loader and described two variants that differ in shellcode execution and injection methods. They also documented persistence via Windows services or lookalike executables in SysWOW64 and a runtime string-mutation feature to hinder analysis.

Dec 23, 20256mo ago

Cryptomining malware reaches built-in cleanup date

The cryptomining malware contains a hardcoded check for December 23, 2025, after which it switches to a cleanup mode that terminates components and deletes dropped files. This suggests the operators planned a defined campaign lifecycle.

Nov 1, 20258mo ago

Trellix identifies USB-spreading cryptomining campaign

Trellix said it identified a multi-stage cryptomining campaign in late 2025 that propagates through USB and external drives, including into air-gapped environments. The malware uses watchdog processes, kills security tools, and leverages the vulnerable WinRing0x64.sys driver for kernel access.

Aug 1, 202511mo ago

Foxveil malware loader activity begins

CATO CTRL assessed that the previously undocumented Foxveil malware loader has been active since August 2025. The loader abuses Cloudflare Pages, Netlify, and Discord attachments to stage shellcode and evade reputation-based defenses.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

33 LINKEDOpen in app
Threat actors
1 linked
Affected products
13 linked
FortigateFortimailFortiguard AntivirusFortisandboxFortiedrForticlientForticlientWindowsWindows ExplorerPowershell.Net FrameworkWindows Script HostLinux
Organizations
14 linked
Microsoft CorporationTrend MicroFortinetBroadcomTrellixLevelBlueDiscordMalwarebytesBanco BradescoCato NetworksCloudflareCloudinaryAny.RunNetlify
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.