“Your shipment has arrived” email hides remote access software

2026-04-17T08:51:52Z95261733557c87748b2642c3adedce19630fe34c5808d30931bcfa8c8c166cf0
Adobe-ReaderClickFixOmnistealerPlugXPushpagandaRATaccount-takeovercredential-theftdata-breachemail-lurefake-softwareinfostealermacOS-malwaremalspampatch-tuesdayphishingpush-notification-fraudransomwareremote-access-trojanscamstrojanized-installerzero-day

What happened

Malwarebytes Labs roundup (April 2026) describing multiple active phishing and malware campaigns and broader security issues: DHL-themed emails delivering remote-access software (RATs) that enable follow-on ransomware; trojanized Slack and Claude installers that give attackers hidden/invisible desktops and deploy PlugX; a prolific Windows infostealer (including Omnistealer) spreading via fake VPN sites, gaming mods and GitHub; an Adobe Reader zero‑day that was exploited in the wild (urgent patching advised); a Patch Tuesday addressing 167 vulnerabilities including two zero‑days (one under live

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
95261733557c87748b2642c3adedce19630fe34c5808d30931bcfa8c8c166cf0
Enrichment time
2026-04-17T08:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.