Multiple phishing campaigns used Adobe-themed document lures and trusted cloud platforms to gain remote access on victim systems. Cloudflare and CyberArmor reported broad activity abusing Vercel-hosted pages that impersonated PDF viewers, invoices, shipping notices, legal alerts, and account warnings, then delivered executables or selectively served payloads after fingerprinting visitors through Telegram-based filtering. Rather than relying solely on custom malware, the operators frequently installed legitimate remote management software such as GoTo Resolve/LogMeIn, turning signed admin tools into living-off-the-land backdoors while hiding behind trusted domains including vercel.app and similar hosting services.
A separate but related spear-phishing operation targeted Pakistan's Punjab Safe Cities Authority (PSCA) and PPIC3 with a fake "Safe Jail Project" email carrying a VBA-stomped Word file and a PDF lure. Joe Sandbox found the Word document fetched code.exe from BunnyCDN infrastructure, invoked Microsoft's VS Code tunnel service for covert persistence, and sent compromise notifications to an attacker-controlled Discord webhook, while the PDF pushed victims toward an unsigned ClickOnce manifest masquerading as an Adobe update. The reporting shows a consistent pattern of attackers blending malicious delivery with legitimate services, signed remote-access tools, and staged payloads to evade detection and maintain control of compromised hosts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
GBHackers reported on Joe Sandbox's findings, highlighting the campaign's obfuscation, staged payload delivery, BunnyCDN-hosted infrastructure, VS Code tunnel abuse, and Discord-based exfiltration against Pakistan government-linked organizations.
Joe Sandbox released a malware analysis report on the PSCA/PPIC3 spear-phishing operation, rating the Word document 100/100 malicious and confirming dropped files, malicious network indicators, and Discord and VS Code tunnel activity. The report noted the tooling appeared custom and that no definitive malware family or threat actor attribution was possible because the final Adobe.exe stage was unavailable.
Analysis of the PSCA/PPIC3 campaign showed the Word document downloading and executing code.exe from BunnyCDN-hosted infrastructure, then abusing Microsoft's VS Code tunnel service for persistent remote access while sending compromise notifications to an attacker-controlled Discord webhook. The PDF lure displayed a fake Adobe Reader update prompt leading to an unsigned ClickOnce manifest intended to fetch a next-stage payload.
A separate targeted campaign struck employees of the Punjab Safe Cities Authority and PPIC3 using emails themed around a supposed government 'Safe Jail Project.' The messages carried a VBA-stomped Word document and a PDF lure with typosquatted filenames to initiate infection.
Over roughly the prior two months, CyberArmor observed more than 28 campaigns using malicious Vercel-hosted pages impersonating Adobe PDF viewers to trick victims into downloading executables such as Invoice06092025.exe.bin. After execution, the malware installed itself and connected to LogMeIn infrastructure for remote access.
Cloudflare published research detailing the Vercel-hosted phishing operation, its use of trusted subdomains and legitimate remote management software, and the campaign's evolution toward Telegram-assisted filtering and selective payload delivery.
By January 2026, the Vercel-hosted campaign had shifted from simpler public file-dropper delivery to a Telegram-based conditional delivery model that fingerprinted visitors, exfiltrated victim metadata, and selectively served payloads to evade sandboxes and researchers.
A phishing campaign became active in November 2025, using trusted Vercel-hosted pages and lures such as invoices, shipping documents, legal notices, security updates, and business alerts to deliver remote access software. The operators relied on legitimate signed remote management tooling, including GoTo Resolve/LogMeIn, rather than custom malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
gbhackers.com
Open sourcejoesandbox.com
Open sourcecyberarmor.tech
Open sourcecloudflare.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.