Hiring Lures Now Deliver Stealthier Spyware

Screening Serpens is no longer just running a lure campaign. It has shifted to a more resilient intrusion set that pairs trusted-brand recruiting bait with AppDomainManager hijacking and multiple bespoke RATs, so simple email filtering and commodity malware detection are less likely to catch it before persistence lands on the endpoint. Unit 42 says the group ran fresh activity from mid-February through April 2026 and found six new RAT variants deployed across coordinated espionage campaigns. Targets included personnel in the U.S., Israel, the UAE, and other Middle Eastern entities, with the main focus on technology and defense workers. The mix of tailored lures and loader hijacking points to a capability jump, not a one-off campaign. That matters because the first visible artifact may already be a trusted process being abused, not an obvious malicious file.

Part of the PlainSec briefing for 2026-05-23

Sources