This old-school scam is still working

2026-04-17T20:51:54Z51593baba854e3c3b1b909ae550ce954f32bef43af0acbdb0e5e5bdaa117982a
adobe-readerai-drivencredential-theftdata-breachinfostealermacosmalwareomnistealerpatch-tuesdayphishingplugxpush-notificationspushpagandaransomwareremote-access-trojanscamssocial-engineeringtrojanized-installerwindowszero-day

What happened

A Malwarebytes Labs roundup of active threats and scams from April 2026: multiple social‑engineering campaigns (advance‑fee/Nigerian scams, iCloud and Amazon impersonations, fake shipment and copyright notices) are being used to steal credentials and payment data. Several malware campaigns are highlighted — trojanized Slack and Claude installers (hidden desktop/PlugX), Windows infostealers/Omnistealer, macOS ClickFix infections, and a DHL-themed email that pushes remote‑access software useful for later ransomware deployment. The feed also notes high‑risk vulnerabilities: April Patch Tuesday (2

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
51593baba854e3c3b1b909ae550ce954f32bef43af0acbdb0e5e5bdaa117982a
Enrichment time
2026-04-17T20:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.