Multiple reports describe distinct malware and intrusion campaigns active across enterprise, government, developer, and consumer targets, rather than a single shared incident. The activity includes vishing-led abuse of Quick Assist for remote access and persistence, a .NET AOT malware chain delivering Rhadamanthys and XMRig, renewed Horabot banking Trojan activity using fake CAPTCHA and mshta, a compromised Open VSX extension that fetched BlokTrooper payloads, and a Middle East-focused Ramadan coupon lure delivering a RAT with AWS S3-based exfiltration. Additional reporting covers Operation CamelClone, which used government-themed spear-phishing and LNK files to steal data with Rclone, and Contagious Trader, a cryptocurrency-focused campaign tied to malicious GitHub and npm projects.
One reference stands apart as vulnerability research rather than campaign reporting: watchTowr detailed pre-authenticated RCE chains in BMC FootPrints, which is a separate product security disclosure and not part of the malware operations described elsewhere. Because the references cover unrelated incidents, malware families, and victim sets, the material should not be treated as one cohesive event. It is also not fluff, as the sources contain substantive threat intelligence, technical analysis, exploit research, and incident tradecraft rather than marketing or generic advice.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
A follow-on report highlighted Horabot's re-emergence in Mexico, summarizing the multi-stage phishing chain, email worm behavior, and the scale of infections previously uncovered by researchers. The report reinforced that the campaign had been active since May 2025 and heavily targeted Mexican users.
Blackpoint Security described an intrusion in which a threat actor impersonated IT support over voice calls and convinced a user to grant access through Microsoft Quick Assist. After access, the operator staged payloads, used Node.js and Deno for modular follow-on malware, and activity was linked with high confidence to the Tsundere Netto botnet.
Aikido disclosed that multiple fast-draft extension versions published to Open VSX were malicious, while other versions appeared clean, suggesting a compromised publisher account or stolen publishing token. The second-stage payload deployed the BlokTrooper framework, including a Socket.IO RAT, browser and wallet theft, document exfiltration, and clipboard monitoring across Windows, macOS, and Linux.
Securelist documented the active Horabot campaign's fake CAPTCHA lure, mshta-based execution chain, Delphi banking trojan payload, and PowerShell email spreader. The report also released YARA rules, a Suricata signature, hunting guidance, and indicators of compromise for detection.
CloudSEK reported a socially engineered campaign using fake Ramadan discount offers and a malicious document impersonating AlCoupon to target Windows users in the Middle East. The infection chain used a hidden VBA macro and C# loader to deploy the Ftu4You RAT, with exfiltration routed through AWS S3 presigned URLs.
Howler Cell identified a multi-stage malware campaign using .NET Ahead-of-Time compilation to hinder analysis and evade detection. The chain used a ZIP-delivered loader to fetch additional payloads, including the Rhadamanthys infostealer and an XMRig miner, while a host-scoring system screened out sandbox environments.
A large campaign dubbed Contagious Trader used malicious GitHub cryptocurrency trading bot repositories and 37 npm packages to steal private keys, sensitive files, and establish persistence, including SSH backdoors on some Linux systems. The activity was attributed with high confidence to North Korean operators based on overlaps with Lazarus-linked tradecraft and infrastructure patterns.
Operation CamelClone targeted government, defense, and diplomatic organizations in Algeria, Mongolia, Ukraine, and Kuwait with spear-phishing ZIP archives disguised as official correspondence. The infection chain used LNK files, hidden PowerShell, the HOPPINGANT JavaScript loader, and Rclone to steal documents and Telegram Desktop session data via public file-sharing sites and MEGA.
Researchers disclosed the malicious fast-draft Open VSX extension activity to the maintainer via GitHub issue #565. The issue was opened on March 12, 2026 and remained unanswered at the time of reporting.
Researchers identified four MEGA accounts linked to Operation CamelClone that were created in February and March 2026. The accounts were used as part of the campaign's cloud-based exfiltration and staging infrastructure.
Huntress documented a February 2026 intrusion cluster affecting five partner organizations in which attackers used spam emails and fake IT support calls to obtain QuickAssist or RMM access, harvest credentials through a fake Outlook Antispam Control Panel, and deploy customized Havoc Demon payloads via DLL sideloading. The operators moved to nine additional endpoints within about eleven hours and used modified Havoc features, including registry-based fallback C2 recovery, while tradecraft overlapped with Black Basta and FIN7-style activity.
An exposed Horabot victim panel showed infections dating back to May 2025, with 5,384 victims recorded and about 93% located in Mexico. The campaign used Spanish-language lures while infrastructure and code artifacts suggested Brazilian operator ties.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceblackpointcyber.com
Open sourcehackread.com
Open sourcecloudsek.com
Open sourcesecurelist.com
Open sourceaikido.dev
Open sourcecybersecuritynews.com
Open sourcekmsec.uk
Open sourcehuntress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.