Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
initial-access-methodphishing-campaign-intelligenceransomware-group-operationremote-access-implant

Mixed threat reporting: APT campaigns, malware delivery via compromised web assets, and ransomware exploitation

Updated 3mo agoFirst seen Feb 24, 20267 sources

The provided items do not describe a single cohesive cybersecurity event; they span multiple unrelated threat reports and opinion pieces. Notable incident-level reporting includes APT28 activity in Western/Central Europe (“Operation MacroMaze”) using spear-phishing lures with Office macros that beacon via INCLUDEPICTURE to webhook[.]site and then execute VBScript/CMD/batch stages for persistence and follow-on payload delivery. Separately, MuddyWater (Iran/MOIS-linked) was reported running “Operation Olalampo” against organizations in the Middle East and Africa, delivering new custom malware (including a Char backdoor using a Telegram bot for C2) and, in some cases, attempting exploitation of public-facing servers in addition to phishing.

Criminal activity and initial-access tradecraft were also covered across distinct stories: a DFIR case study described exploitation of Apache ActiveMQ CVE-2023-46604 to gain RCE, conduct post-exploitation (Metasploit/Meterpreter, privilege escalation, LSASS access, lateral movement), and ultimately deploy LockBit-branded ransomware via RDP using previously stolen credentials (with indications the payload was built using the leaked builder and used Session for communications). Multiple reports described malware delivery via compromised web assets and social engineering, including GrayCharlie injecting malicious JavaScript into WordPress sites to push NetSupport RAT, Stealc, and SectopRAT via fake updates/ClickFix-style CAPTCHAs, and a separate ClickFix campaign delivering a custom C++ RAT (MIMICRAT) through fake Cloudflare verification prompts that trick users into running PowerShell. Additional, unrelated threat reporting included a NuGet supply-chain attack (typosquatted NCryptYo plus companion packages) targeting ASP.NET Identity data and enabling backdoored authorization rules, and malicious Chrome extensions using a “Promise Bomb” browser-crash technique to drive users to run fake “CrashFix” PowerShell steps. Several other items were generic commentary/roundups (data breach trends, quantum preparedness, Enigma history, NATO public opinion polling, recon how-to, and a malware-newsletter link list) and do not add event-specific intelligence.

Share:
Mixed threat reporting: APT campaigns, malware delivery via compromised web assets, and ransomware exploitation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

12 events from the most recent confirmed update back to the earliest known activity.

12 EVENTS
Feb 23, 20264mo ago

Group-IB publicly reports new MuddyWater malware set

Group-IB publicly described Operation Olalampo as a fresh MuddyWater campaign and noted that some malware components showed signs consistent with AI-assisted development, including unusual debug strings. The report also released IoCs and detection rules to help defenders identify the activity.

LAB52 attributes MacroMaze campaign to APT28

S2 Grupo's LAB52 publicly attributed Operation MacroMaze to the Russia-linked threat actor APT28 and detailed its webhook-based macro malware workflow. The disclosure highlighted the campaign's use of native tooling and legitimate web services to minimize artifacts and evade detection.

Researchers disclose GrayCharlie targeting of US law firm websites

Researchers reported that at least fifteen US law firm websites were found injected with identical malicious JavaScript pointing to the same attacker domain. They also suspected a supply-chain compromise involving SMB Team, an IT services provider to law firms, based on stolen credentials tied to an SMB Team email address.

Socket reports NuGet supply-chain campaign and seeks takedowns

Socket's Threat Research Team disclosed that the four malicious NuGet packages had accumulated about 4,500 downloads and appeared linked by shared credentials, build artifacts, and metadata quirks. Socket said it submitted takedown requests to the NuGet security team and published defensive guidance for dependency auditing and detection.

Feb 1, 20265mo ago

Elastic identifies MIMICRAT ClickFix campaign

In early February 2026, Elastic analysts reported a multi-stage campaign using compromised websites and fake Cloudflare verification prompts to trick users into running PowerShell commands. The infection chain deployed a custom RAT called MIMICRAT, which supports stealth, persistence, token theft, file manipulation, and SOCKS5 tunneling.

Jan 26, 20265mo ago

Group-IB discovers MuddyWater Operation Olalampo

On January 26, 2026, Group-IB first discovered a new MuddyWater campaign dubbed Operation Olalampo targeting organizations and individuals mainly in MENA and parts of Africa. The activity used phishing documents and sometimes public-facing server exploitation to deliver new malware families including Char, GhostFetch, GhostBackDoor, and HTTP_VIP leading to AnyDesk.

Sep 1, 202510mo ago

APT28 launches Operation MacroMaze against European targets

From September 2025 through January 2026, APT28 conducted a spear-phishing campaign dubbed Operation MacroMaze against entities in Western and Central Europe. The operation used lure documents with INCLUDEPICTURE tracking beacons, evolving macro techniques, and webhook[.]site for command retrieval and exfiltration.

Jan 1, 20251y ago

GrayCharlie infrastructure expands through 2025

Researchers observed two main NetSupport RAT command-and-control clusters associated with GrayCharlie being deployed steadily through 2025. The infrastructure used distinct TLS certificate naming patterns, license keys, and serial numbers, with hosting linked in part to MivoCloud and HZ Hosting Ltd.

Aug 12, 20242y ago

Malicious NuGet packages published to target ASP.NET developers

Between August 12 and August 21, 2024, four malicious NuGet packages — NCryptYo, DOMOAuth2_, IRAOAuth2.0, and SimpleWriter_ — were published by the account "hamzazaheer." The packages were designed to backdoor ASP.NET applications through JIT hooking, localhost proxying, credential and authorization-data theft, and attacker-controlled authorization responses.

Mar 4, 20242y ago

Attacker re-enters via unpatched ActiveMQ flaw and deploys ransomware

Eighteen days after the first intrusion, the same actor returned through the still-unpatched Apache ActiveMQ vulnerability, reused prior C2 infrastructure, enabled RDP, installed AnyDesk, and conducted additional scanning. Ransomware consistent with LockBit, but assessed as likely built with the leaked LockBit builder, was then deployed interactively across servers including backup and file servers.

Feb 15, 20242y ago

Apache ActiveMQ server first exploited for initial access

In mid-February 2024, a threat actor exploited CVE-2023-46604 on an internet-facing Apache ActiveMQ server to gain remote code execution and establish a foothold on a Windows host. The attacker downloaded a Metasploit stager, escalated privileges, dumped LSASS, scanned via SMB, and moved laterally before being evicted about a day later.

Jun 1, 20233y ago

GrayCharlie begins WordPress malware campaign

GrayCharlie has been active since mid-2023, compromising WordPress sites and injecting malicious JavaScript to deliver malware such as NetSupport RAT, Stealc, and SectopRAT to site visitors. The campaign relied on fake browser updates and ClickFix-style fake CAPTCHA lures.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

54 LINKEDOpen in app
Affected products
13 linked
WindowsWkhtmltopdfVirustotalAnydeskAdvanced Ip ScannerAspnetWordpressMetasploit FrameworkWindows Script HostSpring FrameworkApache-ActivemqSpring FrameworkRemote Desktop Protocol (Rdp)
Organizations
25 linked
Microsoft CorporationS2 GrupoElasticSoftperfectFamatechAmazon Web ServicesRapid7SocketApache Software FoundationVirustotalRecorded FutureWordpressAppleAnyDesk Software GmbHGoogleFidelis CybersecurityHZ Hosting Ltd.Spotify Technology S.A.SMB TeamMivoCloudSession Technology FoundationActivitarGerling Law Injury AttorneysWiser UniversityEziriz
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.