“Your shipment has arrived” email hides remote access software
2026-04-17T08:51:52Z•95261733557c87748b2642c3adedce19630fe34c5808d30931bcfa8c8c166cf0
Adobe-ReaderClickFixOmnistealerPlugXPushpagandaRATaccount-takeovercredential-theftdata-breachemail-lurefake-softwareinfostealermacOS-malwaremalspampatch-tuesdayphishingpush-notification-fraudransomwareremote-access-trojanscamstrojanized-installerzero-day
What happened
Malwarebytes Labs roundup (April 2026) describing multiple active phishing and malware campaigns and broader security issues: DHL-themed emails delivering remote-access software (RATs) that enable follow-on ransomware; trojanized Slack and Claude installers that give attackers hidden/invisible desktops and deploy PlugX; a prolific Windows infostealer (including Omnistealer) spreading via fake VPN sites, gaming mods and GitHub; an Adobe Reader zero‑day that was exploited in the wild (urgent patching advised); a Patch Tuesday addressing 167 vulnerabilities including two zero‑days (one under live
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 95261733557c87748b2642c3adedce19630fe34c5808d30931bcfa8c8c166cf0
- Enrichment time
- 2026-04-17T08:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.