March 2026 Phishing Email Trends Report
Essential information
- Published
- 22/04/2026 07:06
- Modified
- 22/04/2026 08:29
- Tags
- 2026-04-22 agenttesla credential-theft fake invoices html phishing phishing email remcosrat script-based attacks trojan campaigns
- Related entities
- 19 techniques (mitre), 2 malware, 3 others
Description
In March 2026, trojans represented 21% of attachment-based threats, while phishing attacks using fake pages dropped from 42% to 15% month-over-month. Script-based malware increased significantly, with HTML at 14% and JavaScript at 11%. Compressed files including ZIP (14%), RAR (8%), and 7Z (5%) were common distribution methods. Document-based threats utilized PDF (13%), XLS (5%), and DOCX (2%) files. Attackers impersonated courier services like FedEx and DHL, as well as financial institutions including Hana Bank and Woori Bank. Distribution methods included HTML scripts and PDF hyperlinks leading to credential-stealing pages. Notable malware families included RemcosRAT and AgentTesla, with command-and-control infrastructure utilizing Telegram API tokens and external mail servers for data exfiltration.