Security researchers warned that corporate users are facing sustained phishing activity that relies heavily on social engineering, including emails impersonating CEOs and executives and messages posing as copyright complaints, business proposals, recruiting outreach, and AI video tool offers. In the executive-impersonation cases, attackers used public webmail services such as Gmail and Hotmail to contact representative and recruiting inboxes, pressured recipients to reply or share messenger chat-room QR codes, and appeared to be conducting reconnaissance for follow-on compromise rather than delivering malware immediately.
A separate long-running campaign tracked as PyChain was attributed to a Vietnam-linked threat actor dubbed LoneNone, which used ZIP archives and disguised executables to infect victims through multi-stage malware delivery. Recent samples abused a fake PDF executable built from ADNotificationManager.exe for DLL sideloading, then fetched an encrypted archive containing Python runtime components and obfuscated scripts that stole browser credentials, cookies, system information, and cryptocurrency wallet data. Researchers said the actor repeatedly changed delivery infrastructure and lures, using services and channels including GitHub, Dropbox, Telegram bots, paste sites, URL shorteners, and attacker-controlled hosts, while expanding phishing content into more than 30 languages.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On publication of its analysis, ESTsecurity's ESRC attributed the long-running global phishing activity to a Vietnam-linked threat actor it calls LoneNone and named the broader intrusion set the PyChain campaign. The report documented the campaign's technical evolution from late 2024 through January 2026.
East Security reported that phishing emails impersonating CEOs and executives were being continuously distributed against major companies. The messages used social engineering rather than immediate malware delivery, attempting to provoke replies or obtain messenger chat-room QR codes from recipients.
By January 2026, ESRC observed samples using a fake PDF executable based on Adobe's ADNotificationManager.exe to sideload a hidden DLL, download an encrypted RAR archive, unpack Python 3.10 runtime files and malicious scripts, and run an obfuscated Python payload. The malware then used Telegram and urlvanish.com to resolve second-stage infrastructure hosted at mongky68.godohosting.com and steal browser data, system information, and cryptocurrency wallet data.
Over more than a year, the PyChain intrusion set expanded across seven operations, adding signed executables for DLL sideloading, Telegram bots, URL shorteners, paste sites, and attacker-controlled infrastructure while keeping Python-based malware at its core. The campaign also broadened its lures beyond legal notices to business proposals, recruiting, and AI video tool themes in more than 30 languages.
A Vietnam-linked threat actor later named LoneNone began a phishing campaign in late 2024 using emails that claimed copyright infringement and lured targets into downloading ZIP archives with disguised executables. Early activity relied on trusted services such as GitHub and Dropbox for payload delivery.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.