{"id":47588,"date":"2026-04-17T03:50:05","date_gmt":"2026-04-17T03:50:05","guid":{"rendered":"http:\/\/localhost\/?p=47588"},"modified":"2026-04-17T03:50:05","modified_gmt":"2026-04-17T03:50:05","slug":"your-shipment-has-arrived-email-hides-remote-access-software","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=47588","title":{"rendered":"\u201cYour shipment has arrived\u201d email hides remote access software_MALWAREBYTES:B2E0AC8DBA63AA895C1F2226CFEA315A"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-04-17T08:05:09&#8243;,&#8221;description&#8221;:&#8221;An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool\u2014an ideal starting point for attackers to explore a network, steal data, and drop additional malware.\\n\\nA German industrial spare parts and equipment supplier received an email pretending to be from DHL, claiming a shipment had arrived.\\n\\n![Screenshot of email pretending to be from DHL](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2026\/04\/mail_screenshot_red.png)\\n\\nGiven their line of business, I imagine they get this type of email all the time. But a few details stood out:\\n\\n  * The sender&#8217;s email address did not belong to DHL,\\n  * the receiver address was the general info@ for the company,\\n  * the images in the email were hosted on `ecp.yusercontent.com`, \\n  * and, most importantly, there was attachment.\\n\\n\\n\\nWhile the remote content is hosted on a legitimate Yahoo webpage commonly used to serve images and other content in Yahoo Mail, this is not something DHL typically uses.\\n\\nThe attachment, a PDF file called `AWB-Doc0921.pdf` is just a blurred image with a Microsoft-branded button that prompts the victim to \u201cContinue\u201d to access a secure file.\\n\\n![blurred content with a Continue button](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2026\/04\/blurred_continue.png)\\n\\nIn reality, clicking the button downloads a file called `AWB-Doc0921.scr` from the domain `longhungphatlogistics[.]vn`, a domain belonging to a Vietnamese logistics company that was likely compromised to host malware.\\n\\n![Malwarebytes blocks longhungphatlogistics\\\\[.\\\\]vn](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2026\/04\/MBAM_block.png)Malwarebytes blocks longhungphatlogistics[.]vn\\n\\nA .`scr` file is a Windows file, which is an executable (`.exe`) file used to launch screensavers. They are often used to hide malicious code because Windows trusts them, allowing them to bypass some security layers. \\n\\nIn this case, the file is a modified installer of a remote access tool signed by SimpleHelp.\\n\\n![UAC prompt for the signed installer](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2026\/04\/UAC_prompt.png)UAC prompt for the signed installer\\n\\nSimpleHelp is a remote support and remote monitoring and management (RMM) platform. It allows remote desktop control, file transfer, diagnostics, and unattended access. In the wrong hands, that&#8217;s effectively a support-style backdoor. Attackers can use it for reconnaissance, credential theft, lateral movement, defense evasion, and staging further malware, including ransomware. We&#8217;ve seen SimpleHelp abused in this way before. \\n\\nThis is basically a beaconing model. Once installed, the system connects out to the attacker&#8217;s server, which is more likely to be allowed through NAT and firewalls than inbound connections. Because the user initiated the install, the attacker gets immediate visibility of the system and can reconnect later whenever the service is running. In the case of a phish, that means the lure only has to get the victim to execute the file once. After that, the attacker\u2019s console can show the new machine as a manageable asset.\\n\\nFor what seems to be a non-targeted attack, the campaign shows a decent level of sophistication by using legitimate components to trick targets into running the remote access tool.\\n\\n## How to stay safe\\n\\nThe good news: once you know what to look for, these attacks are much easier to spot and block. The bad news: they\u2019re cheap, scalable, and will continue to circulate.\\n\\nSo, the next time a \u201cPDF\u201d prompts you to download a file, pause to think about what might be hiding under the hood.\\n\\nBeyond avoiding unsolicited attachments, here are a few ways to stay safe:\\n\\n  * Only access your accounts through official apps or by typing the official website directly into your browser.\\n  * Check file extensions carefully. Even if a file installs a legitimate tool, it may not be safe to run it.\\n  * Enable multi-factor authentication for your critical accounts.\\n  * Use an up-to-date, real-time anti-malware solution with a web protection module.\\n\\n\\n\\nPro tip: Malwarebytes Scam Guard recognized this email as a scam.\\n\\n* * *\\n\\n### **Something feel off? Check it before you click.  ** \\n\\n**Malwarebytes Scam Guard** helps you analyze suspicious links, texts, and screenshots instantly. \\n\\nAvailable with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  \\n\\nTry it free \u2192&#8221;,&#8221;published&#8221;:&#8221;2026-04-17T07:40:03&#8243;,&#8221;modified&#8221;:&#8221;2026-04-17T07:40:03&#8243;,&#8221;type&#8221;:&#8221;malwarebytes&#8221;,&#8221;title&#8221;:&#8221;\u201cYour shipment has arrived\u201d email hides remote access software&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;MALWAREBYTES:B2E0AC8DBA63AA895C1F2226CFEA315A&#8221;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/www.malwarebytes.com\/blog\/news\/2026\/04\/your-shipment-has-arrived-email-hides-remote-access-software&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-04-17T08:05:09&#8243;,&#8221;description&#8221;:&#8221;An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool\u2014an ideal starting point for attackers&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,115,13,33,7,11,5],"class_list":["post-47588","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-malwarebytes","tag-news","tag-none","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\u201cYour shipment has arrived\u201d email hides remote access software_MALWAREBYTES:B2E0AC8DBA63AA895C1F2226CFEA315A - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=47588\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u201cYour shipment has arrived\u201d email hides remote access software_MALWAREBYTES:B2E0AC8DBA63AA895C1F2226CFEA315A - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-04-17T08:05:09&#8243;,&#8221;description&#8221;:&#8221;An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool\u2014an ideal starting point for attackers...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=47588\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-17T03:50:05+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47588#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47588\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\u201cYour shipment has arrived\u201d email hides remote access software_MALWAREBYTES:B2E0AC8DBA63AA895C1F2226CFEA315A\",\"datePublished\":\"2026-04-17T03:50:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47588\"},\"wordCount\":861,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"malwarebytes\",\"news\",\"NONE\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=47588#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47588\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47588\",\"name\":\"\u201cYour shipment has arrived\u201d email hides remote access software_MALWAREBYTES:B2E0AC8DBA63AA895C1F2226CFEA315A - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-04-17T03:50:05+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47588#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=47588\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=47588#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u201cYour shipment has arrived\u201d email hides remote access software_MALWAREBYTES:B2E0AC8DBA63AA895C1F2226CFEA315A\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\u201cYour shipment has arrived\u201d email hides remote access software_MALWAREBYTES:B2E0AC8DBA63AA895C1F2226CFEA315A - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=47588","og_locale":"en_US","og_type":"article","og_title":"\u201cYour shipment has arrived\u201d email hides remote access software_MALWAREBYTES:B2E0AC8DBA63AA895C1F2226CFEA315A - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-04-17T08:05:09&#8243;,&#8221;description&#8221;:&#8221;An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool\u2014an ideal starting point for attackers...","og_url":"https:\/\/zero.redgem.net\/?p=47588","og_site_name":"zero redgem","article_published_time":"2026-04-17T03:50:05+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=47588#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=47588"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\u201cYour shipment has arrived\u201d email hides remote access software_MALWAREBYTES:B2E0AC8DBA63AA895C1F2226CFEA315A","datePublished":"2026-04-17T03:50:05+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=47588"},"wordCount":861,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","malwarebytes","news","NONE","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=47588#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=47588","url":"https:\/\/zero.redgem.net\/?p=47588","name":"\u201cYour shipment has arrived\u201d email hides remote access software_MALWAREBYTES:B2E0AC8DBA63AA895C1F2226CFEA315A - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-04-17T03:50:05+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=47588#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=47588"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=47588#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\u201cYour shipment has arrived\u201d email hides remote access software_MALWAREBYTES:B2E0AC8DBA63AA895C1F2226CFEA315A"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/47588","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=47588"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/47588\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=47588"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=47588"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=47588"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}