Multiple reports describe phishing-led malware delivery that abuses trusted services and “living off the land” execution paths to evade controls and deploy remote access tooling. Cloudflare-tracked activity shows attackers using Vercel-hosted pages to lend legitimacy to malicious links and bypass email/security filtering, with lures themed around invoices, payments, shipping, and document portals; the infrastructure includes Telegram-based filtering and browser fingerprinting/conditional delivery to hinder researchers and sandboxes before serving payloads that install a remote access tool (RAT).
A separate campaign (tracked as PHALT#BLYX) targets hospitality staff with Booking[.]com-style reservation emails and uses a fake browser error + fake BSOD to coerce victims into running the ClickFix technique (Win+R paste/execute), launching PowerShell that pulls malicious project files and executes them via MSBuild.exe to deliver DCRat, consistent with LOLBins-based evasion; researchers noted Russian-language artifacts in the malware. Broader weekly/newsletter roundups also highlight the same risk theme—attackers increasingly blend social engineering with trusted infrastructure and tools—while mixing in unrelated items (e.g., firewall CVEs, general malware research links) that are not part of a single, specific incident narrative.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
In April 2026, ANY.RUN reported a phishing campaign abusing storage.googleapis.com to host fake Google Drive login pages that steal credentials and one-time passcodes before delivering a multi-stage infection chain. The attack used JavaScript, VBS, PowerShell, an in-memory .NET loader from Textbin, and process hollowing via Microsoft-signed RegSvcs.exe to deploy Remcos RAT.
On January 26, 2026, Cloudflare analysts reported that the Vercel-based phishing campaign had evolved from earlier activity, adding Telegram-based filtering to block researchers and sandboxes from reaching the payload. The report also detailed the use of fake document viewers and signed GoTo Resolve binaries to gain full remote control of victim systems.
Analysis published on January 26, 2026 described how the PHALT#BLYX infection chain weakened Windows Defender with broad exclusions, attempted privilege escalation through repeated UAC prompts, and deployed an obfuscated DCRat variant for persistence, reconnaissance, keylogging, and remote access. The report highlighted the campaign's use of living-off-the-land techniques and potential for follow-on actions such as credential theft or ransomware deployment.
By January 2026, a campaign tracked as PHALT#BLYX was targeting hospitality businesses with phishing emails posing as Booking.com reservation cancellation notices. Victims were redirected to fake Booking.com pages using fake browser errors, a simulated BSOD, and ClickFix social engineering to launch PowerShell and execute malware via MSBuild.exe.
Between November 2025 and January 2026, threat actors continued a phishing campaign that abused Vercel's legitimate hosting platform with lures such as invoices, payment statements, shipping documents, and fake document portals. The operation used browser fingerprinting and Telegram-based target validation before delivering a signed copy of GoTo Resolve for remote access.
In June 2025, CyberArmor first documented a phishing campaign abusing Vercel-hosted pages to deliver malware and remote access tooling. This established the earlier known activity later analyzed by Cloudflare.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.