SeasonalInvite eCard phishing campaign targeting Windows and macOS users
Campaign
Summary
Hide ▲
Show ▼
The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards. The operation used 959 domains and a traffic distribution system (TDS) to route victims to a BlueMountain impersonation page that auto-downloaded an installer. The campaign matters because the installers were commercially signed and therefore could pass normal security checks while still enabling attacker-controlled remote access.
Related Happenings
Operation BlueDash Microsoft Teams phishing campaign delivering Level RMM and ScreenConnect
Campaign
H score45
First: 27.07.2026 15:37
Last: 27.07.2026 15:37
Sources 1
About this happening:
The Operation BlueDash phishing campaign is using a fake Microsoft Teams update flow to install Level RMM and ConnectWise ScreenConnect, creating persistent remote...
Operation BlueDash Microsoft Teams phishing campaign delivering Level RMM and ScreenConnect
CampaignAbout this happening: The Operation BlueDash phishing campaign is using a fake Microsoft Teams update flow to install Level RMM and ConnectWise ScreenConnect, creating persistent remote...
Mexico CURP lure .NET infostealer delivery
Malware Activity
H score21
First: 20.07.2026 20:29
Last: 20.07.2026 20:29
Sources 1
About this happening:
A .NET infostealer delivery operation now threatens Windows users in Mexico by using a CURP typosquat and WebDAV path abuse to reach victims. The payload arrived t...
Mexico CURP lure .NET infostealer delivery
Malware ActivityAbout this happening: A .NET infostealer delivery operation now threatens Windows users in Mexico by using a CURP typosquat and WebDAV path abuse to reach victims. The payload arrived t...
Gobf[.]mx CURP typosquat phishing campaign targeting Mexican users
Campaign
H score25
First: 20.07.2026 20:29
Last: 20.07.2026 20:29
Sources 1
About this happening:
The gobf[.]mx operation used a CURP typosquat, a fake record-retrieval page, and WebDAV delivery to push malware at Windows users in Mexico, creating a live phishi...
Gobf[.]mx CURP typosquat phishing campaign targeting Mexican users
CampaignAbout this happening: The gobf[.]mx operation used a CURP typosquat, a fake record-retrieval page, and WebDAV delivery to push malware at Windows users in Mexico, creating a live phishi...
SleeperGem RubyGems supply-chain campaign
Campaign
H score17
First: 20.07.2026 08:15
Last: 20.07.2026 08:15
Sources 1
About this happening:
SleeperGem is an active RubyGems supply-chain campaign that used three malicious gems to stage second payloads, evade CI environments, and persist on developer m...
SleeperGem RubyGems supply-chain campaign
CampaignAbout this happening: SleeperGem is an active RubyGems supply-chain campaign that used three malicious gems to stage second payloads, evade CI environments, and persist on developer m...
CrashStealer meeting-PIN delivery campaign
Campaign
H score35
First: 13.07.2026 22:04
Last: 13.07.2026 22:04
Sources 1
About this happening:
The CrashStealer campaign is delivering a signed, Apple-notarized installer from a fake software site gated by a meeting PIN, narrowing infection opportunities to...
CrashStealer meeting-PIN delivery campaign
CampaignAbout this happening: The CrashStealer campaign is delivering a signed, Apple-notarized installer from a fake software site gated by a meeting PIN, narrowing infection opportunities to...
Timeline
-
15.07.2026 18:00 2 articles · 13d ago
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
Initial DisclosureEarly activity used tax and Social Security lures, then rotated to Valentine's, Easter, and spring invitation themes. Victims who reached the fake greeting-card page were funneled through a TDS to an installer that matched their operating system.
Show sources
- Phishing Campaign Abuses eCards to Deploy RMM Tools — www.infosecurity-magazine.com — 15.07.2026 18:00
- Phishing Campaign Abuses eCards to Deploy RMM Tools — www.infosecurity-magazine.com — 15.07.2026 18:00