Skip to content
Phorpiex Phishing Campaign Uses Weaponized Windows Shortcuts

Phorpiex Phishing Campaign Uses Weaponized Windows Shortcuts

First seen 10 Feb 2026, 22:20 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

A phishing campaign leveraging the Phorpiex malware has been identified, utilizing weaponized Windows shortcut files to deliver Global Group ransomware. The campaign, which began in late 2024 and continues into 2026, employs emails with the subject line 'Your Document' to deceive recipients into opening malicious attachments that initiate a multi-stage infection chain.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 196d ago How this analysis works

Timeline

2024-12-01
Phorpiex phishing campaign observed using 'Your Document' emails
2025-01-01
Campaign identified as leveraging weaponized Windows shortcut files
2026-02-10
Forcepoint issues advisory on ongoing Phorpiex campaign

More articles in this cluster (9)

Following this threat?

Track Global Group and Mamona in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed