216.73.217.22

March 2026 Phishing Email Trends Report

· Published 22/04/2026 07:06 · Modified 22/04/2026 08:29

Export JSON

Essential information

Published
22/04/2026 07:06
Modified
22/04/2026 08:29
Tags
2026-04-22 agenttesla credential-theft fake invoices html phishing phishing email remcosrat script-based attacks trojan campaigns
Related entities
19 techniques (mitre), 2 malware, 3 others

Description

In March 2026, trojans represented 21% of attachment-based threats, while phishing attacks using fake pages dropped from 42% to 15% month-over-month. Script-based malware increased significantly, with HTML at 14% and JavaScript at 11%. Compressed files including ZIP (14%), RAR (8%), and 7Z (5%) were common distribution methods. Document-based threats utilized PDF (13%), XLS (5%), and DOCX (2%) files. Attackers impersonated courier services like FedEx and DHL, as well as financial institutions including Hana Bank and Woori Bank. Distribution methods included HTML scripts and PDF hyperlinks leading to credential-stealing pages. Notable malware families included and , with command-and-control infrastructure utilizing Telegram API tokens and external mail servers for data exfiltration.

External references