This old-school scam is still working
2026-04-17T20:51:54Z•51593baba854e3c3b1b909ae550ce954f32bef43af0acbdb0e5e5bdaa117982a
adobe-readerai-drivencredential-theftdata-breachinfostealermacosmalwareomnistealerpatch-tuesdayphishingplugxpush-notificationspushpagandaransomwareremote-access-trojanscamssocial-engineeringtrojanized-installerwindowszero-day
What happened
A Malwarebytes Labs roundup of active threats and scams from April 2026: multiple social‑engineering campaigns (advance‑fee/Nigerian scams, iCloud and Amazon impersonations, fake shipment and copyright notices) are being used to steal credentials and payment data. Several malware campaigns are highlighted — trojanized Slack and Claude installers (hidden desktop/PlugX), Windows infostealers/Omnistealer, macOS ClickFix infections, and a DHL-themed email that pushes remote‑access software useful for later ransomware deployment. The feed also notes high‑risk vulnerabilities: April Patch Tuesday (2
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 51593baba854e3c3b1b909ae550ce954f32bef43af0acbdb0e5e5bdaa117982a
- Enrichment time
- 2026-04-17T20:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.