Multiple active malware campaigns are using social engineering and trojanized content to compromise Windows systems, with lures ranging from pirated software downloads to business and shipping documents. AhnLab reported a “proxyjacking” operation attributed to Larva-25012 that distributes fake installers (notably a trojanized Notepad++ package) via cracked-software sites; the Setup.zip bundle includes a legitimate Setup.exe plus a malicious sideloaded DLL (TextShaping.dll) that decrypts and installs DPLoader for persistent command retrieval and follow-on payload delivery. The malware also tampers with defenses by changing Microsoft Defender settings (e.g., exclusions, reduced notifications, and blocking sample submission) to reduce detection while monetizing victims’ bandwidth through installed proxyware.
Separately, FortiGuard Labs described a Russia-focused, multi-stage intrusion chain that abuses trusted services (GitHub and Dropbox) for payload hosting and weaponizes Defendnot (a Windows Security Center trust-model research tool) to disable Microsoft Defender before deploying a ransomware payload. Fortinet also documented phishing campaigns using weaponized shipping-themed Word documents to deliver Remcos RAT, including fileless execution behavior and exploitation of CVE-2017-11882 (Microsoft Equation Editor) via remotely fetched templates. These campaigns reinforce the operational risk from user-driven execution paths (pirated installers and document lures), “living off the land” techniques, and defense evasion through both policy tampering and security tooling abuse.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
AhnLab Security Intelligence Center warned that threat actor Larva-25012 is distributing trojanized Notepad++ installers through fake software download sites aimed at users seeking cracked or pirated software. The malware uses DLL side-loading to install DPLoader, weakens Windows Defender, persists via scheduled tasks, and monetizes victims by installing proxyware such as Infatica and DigitalPulse.
FortiGuard Labs disclosed a multi-stage campaign targeting users in Russia that uses business-themed decoy documents, weaponized Defendnot to disable Microsoft Defender, and payload hosting on GitHub and Dropbox. The intrusion deploys Amnesia RAT and later ransomware and WinLocker components for persistent control, credential theft, and data denial.
Fortinet analysts reported a phishing campaign using fake shipping emails with malicious Word documents that fetch remote templates and exploit CVE-2017-11882 to install Remcos RAT. The attack uses fileless execution, scheduled-task persistence, and TLS command-and-control to evade detection and maintain access on Windows systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityonline.info
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.