Infosecurity-Magazine Phorpiex Phishing Campaign Uses Weaponized Windows Shortcuts
Article Content
Browse articles
A phishing campaign leveraging the Phorpiex malware has been identified, utilizing weaponized Windows shortcut files to deliver Global Group ransomware. The campaign, which began in late 2024 and continues into 2026, employs emails with the subject line 'Your Document' to deceive recipients into opening malicious attachments that initiate a multi-stage infection chain.
Ask AI about this cluster
Answers cite the sources they use
Updated 196d ago How this analysis works
Timeline
2024-12-01
Phorpiex phishing campaign observed using 'Your Document' emails
2025-01-01
Campaign identified as leveraging weaponized Windows shortcut files
2026-02-10
Forcepoint issues advisory on ongoing Phorpiex campaign
More articles in this cluster (9)
Following this threat?
Track Global Group and Mamona in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
ShinyHunters Breaches Clop Ransomware Site, Initiates Extortion Threat The ShinyHunters extortion gang successfully hacked the Clop ransomware operation's data leak site, exploiting an unauthenticated file upload vulnerability in Grav CMS. They defaced the site with their branding and a warning message, claiming to have stolen sensitive data including source code, system logs, and…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…