HP Threat Research Blog HP Wolf Security Threat Insights Report: March 2026

March 3, 2026 Category: Threat Insights Reports By: HP Wolf Security Comments: 0

HP Wolf Security Threat Insights Report: March 2026

Welcome to the March 2026 edition of the HP Wolf Security Threat Insights Report. In the report, we review notable malware campaigns, trends and techniques identified from HP Wolf Security’s customer telemetry in calendar Q4 2025.

Key Findings

  • Threat actors in Q4 reused the same inexpensive, off the shelf components across multiple campaigns, combining obfuscated scripts, archive.org hosted images carrying embedded code, and a .NET loader to deliver different payloads. Despite variations in lures and initial file types, the infection chains used an identical intermediate malware stage that enabled delivery of payloads such as DarkCloud and AsyncRAT.
  • Attackers used PDF lures relying on a simple but effective technique of directing victims to a compromised website that delivers a malicious download, before immediately redirecting them to a legitimate website to create the impression that the trusted platform initiated the download. This credibility boost helped mask the delivery of scripts and loaders that ultimately deployed Formbook and XWorm. The loader used in these campaigns showed signs of being developed with the help of AI tools, part of a growing trend of threat actors relying on AI coding assistants.
  • Attackers deployed fake websites imitating software applications like Microsoft Teams, tricking users into downloading malicious installers. These silently delivered malware alongside the legitimate Teams application. The installer used dynamic link library (DLL) sideloading through a signed CapCut executable to load a malicious DLL that installs the OysterLoader backdoor, enabling additional malware to be deployed, such as ransomware.
  • Office documents remain an active delivery method in Asia Pacific, where Word and Excel files with simple VBA macros continue to install PowerShell-based loaders. These campaigns ultimately deploy Agent Tesla, configured to harvest local email contacts and communicate with malware operators through Telegram channels.

Read the Report

Download the report: HP Wolf Security Threat Insights Report: March 2026

Download (PDF)

You can download and read our previous Threat Insights Reports here.

About the Author

HP Wolf Security

Recent Posts

2026-03-03T08:03:35+00:00March 3rd, 2026|Threat Insights Reports|