Researchers reported multiple malware delivery campaigns using malicious email, fake browser updates, and likely content injection on compromised websites to install infostealers and remote access trojans. One campaign abused WordPress sites to present a fake Google Chrome update that delivered credential-stealing malware, while another used malicious PEC email lures tied to crypto-wallet themes to infect targets with remote access tooling and theft-focused payloads. Separate reporting also described spam operations distributing evasive malware through email, showing continued reliance on social engineering and web-based lures to gain initial access.
The activity aligns with attacker use of MITRE ATT&CK techniques including T1659 for content injection and T1555 for stealing credentials from password stores. Once installed, these malware families commonly target saved passwords and account data from browsers, email clients, FTP/SFTP tools, Wi-Fi profiles, and Windows credential stores using utilities and methods associated with tools such as LaZagne, Mimikatz, MailPassView, and Network Password Recovery. The campaigns underscore a persistent threat pattern in which adversaries combine deceptive delivery methods with credential theft to expand access, move laterally, and compromise additional systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
certego.net
Open sourcecertego.net
Open sourceattack.mitre.org
Open sourcecertego.net
Open sourcecertego.net
Open sourcecertego.net
Open sourcecertego.net
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.