Skip to main content
Rethinking Email Security for the AI Era, August 25th
Blog
Email Security

How Malware Is Delivered Through Email: A Complete Guide to Every Delivery Method, File Type, and Defense Strategy

AUGUST 7, 202628 MIN READ
Adaptive TeamAdaptive Team
How Malware Is Delivered Through Email: A Complete Guide to Every Delivery Method, File Type, and Defense Strategy

Key takeaways

  • Attackers rely on three delivery methods. Malicious attachments, embedded links, and multi-stage campaigns that chain credential theft to malware deployment each exploit a different gap in the security stack.
  • Old defenses pushed attackers toward new tricks. Microsoft's Mark-of-the-Web restrictions collapsed macro-based attacks, so attackers shifted to password-protected archives, HTML smuggling, QR codes, and AI-generated social engineering.
  • Detection speed matters as much as prevention. Once malware executes, lateral movement across a network can begin in as little as 4 minutes, according to ReliaQuest's 2026 threat analysis.
  • Training remains the last line of defense. No technical filter blocks every threat, so structured security awareness training and realistic phishing simulations give employees the final opportunity to stop an attack before it spreads.

How malware is delivered through email has evolved far beyond the suspicious attachment from an unknown sender. Today's attacks use brand impersonation, password-protected archives, HTML smuggling, and AI-generated social engineering to bypass technical defenses and exploit human decision-making at scale.

This guide examines every delivery method attackers use, from malicious attachments and embedded links to multi-stage hybrid campaigns, and catalogs the file types, malware families, and social engineering tactics that make email the dominant infection vector. Security professionals and IT leaders will find actionable defense frameworks.

The AV-TEST Institute registers over 450,000 new malware programs daily, and ransomware-as-a-service operations like LockBit and REvil have industrialized email-based delivery to the point where non-technical criminals can launch sophisticated campaigns.

By understanding exactly how these attacks unfold, from the initial reconnaissance email to lateral movement and data exfiltration, organizations can build layered defenses that reduce the probability of compromise before a single endpoint is infected.

Organizations seeking to protect their companies from malware, ransomware, and other email-based threats are encouraged to explore an Adaptive Security self-guided tour.

Malware delivered through email warning alert displayed on laptop screen.

What Is Email-Delivered Malware?

Email-delivered malware is malicious software, viruses, trojans, ransomware, spyware, and worms, that reaches an organization through email messages, most commonly as infected attachments or embedded links to weaponized websites.

Unlike drive-by downloads or USB-based infections, email-delivered malware exploits human trust and routine workplace behavior, opening attachments, clicking links, responding to urgent requests, making it both the most common and the most preventable infection vector in enterprise security.

Definition and Scope

Email-delivered malware refers specifically to malicious code that uses email systems as its transport mechanism. This distinguishes it from infection vectors that bypass email entirely: drive-by downloads that execute when a user visits a compromised website, USB-borne malware that spreads through physical media, supply chain attacks that embed malicious code into legitimate software updates, and network-based exploits that target unpatched services directly.

Delivery methods fall into two primary buckets. Attachment-based malware hides inside documents, PDFs, Microsoft Office files with embedded macros, ZIP archives, and increasingly, ISO and LNK files designed to evade automated scanning. Link-based malware directs recipients to a URL hosting a malicious payload, often behind what appears to be a legitimate file-sharing service, invoice portal, or document signature page.

Both approaches share a common dependency: the recipient must take an action. No zero-day exploit, no unpatched server required. The attack chain begins and ends with a human decision.

This reliance on human action is what makes email-delivered malware so persistent across decades of security innovation. Firewalls, endpoint detection, and secure email gateways have grown more sophisticated, yet the fundamental attack vector, convincing someone to open something, has remained effective since the ILOVEYOU worm crippled millions of machines in 2000, causing estimated billions of dollars in damages.

The difference today is scale and precision. Modern attackers use open-source intelligence (OSINT) drawn from LinkedIn, corporate websites, and data broker profiles to craft messages that reference real projects, actual colleagues, and legitimate business workflows. The malware itself may be newly compiled to evade signature-based detection, arriving as a polymorphic threat that no antivirus engine has cataloged.

Key Statistics on Email Malware Volume

The numbers describing email-delivered malware describe an industrial-scale threat pipeline that produces and distributes malicious code faster than most organizations can patch against it.

  • Over 450,000 new malware variants detected daily. The AV-TEST Institute captures the sheer velocity of malicious code production. Each variant represents a potential bypass of yesterday's detection signatures.
  • 62% of breaches involved a human element. The same 2026 Verizon DBIR found that human action, including falling for phishing and opening malicious attachments, was a component in more than two-thirds of all confirmed data breaches, underscoring that email malware is fundamentally a human-layer problem.
  • Phishing and spoofing ranked as the top cybercrime type reported to the FBI. The FBI Internet Crime Complaint Center's 2025 annual report logged phishing, spoofing, and personal data breaches as the most frequently reported offenses, with email serving as the primary delivery mechanism in the vast majority of cases.

The Email Threat Landscape Today

Email-delivered malware occupies a specific position within a broader taxonomy of recognized email-borne threat types: spam, malware, data exfiltration, URL phishing, scamming, spear phishing, domain impersonation, brand impersonation, extortion, business email compromise (BEC), conversation hijacking, lateral phishing, and account takeover.

Within this taxonomy, malware is distinct from phishing and BEC in its technical objective. Phishing campaigns aim to harvest credentials, the email itself is the weapon, and the damage occurs when the target enters their password on a fake login page. BEC attacks manipulate the recipient into transferring funds or sensitive data through social engineering alone, with no malicious code involved.

Email-delivered malware, by contrast, seeks to install software on the target's machine. That software may be ransomware that encrypts files and demands payment, or an information stealer that silently exfiltrates credentials and session tokens. It could also be a remote access trojan (RAT) that grants the attacker persistent control, or a loader that downloads additional payloads once a foothold is established.

These categories increasingly overlap in practice. A single attack campaign might begin with a credential-harvesting phishing email, use the stolen credentials to send malware-laden attachments from a compromised internal account through lateral phishing, and culminate in ransomware deployment.

What makes the current landscape especially dangerous is the erosion of reliable indicators. Ten years ago, a malicious email might contain broken English, an obviously forged sender address, and a suspicious executable attachment.

Today's email-delivered malware arrives in grammatically flawless messages that spoof real vendors and reference actual invoice numbers scraped from compromised accounts. The payloads hide inside file types that users have been trained to trust: PDFs, shared Google Drive links, and DocuSign notifications.

Employees cannot reliably distinguish between a legitimate invoice attachment and an identical-looking malicious one, because there is often no visual difference to detect. Defense must shift from asking individuals to spot malware to giving them the tools and conditioned instincts to verify requests through a second trusted channel before acting, reinforced by regular phishing simulations that build detection reflexes across all the channels attackers now exploit.

Why Email Is the Dominant Vector for Malware Delivery

Email remains the dominant malware delivery channel because it is the only attack vector that combines universal organizational access with an unpatchable vulnerability: human decision-making under pressure.

The persistence of this channel is a rational economic choice: attackers know every employee reads email, and even the best spam filters cannot neutralize a well-timed spear-phishing message crafted to exploit urgency and authority.

Comparing Email to Other Infection Vectors

Drive-by downloads, once a dominant threat, now account for a shrinking fraction of infections as browsers automatically block malicious scripts and organizations adopt stricter endpoint controls.

Watering hole attacks demand the compromise of a specific third-party website frequented by target employees, and supply chain compromises require infiltrating a trusted vendor's update mechanism. Both are high-effort operations with narrow targeting windows that rarely scale.

Email is omnidirectional. A single campaign can reach every employee in an organization simultaneously, across departments, geographies, and access levels. No other vector operates at that scale with that success rate. The asymmetry is what makes email uniquely dangerous: a USB stick can infect one machine; a single malicious attachment can compromise an entire network through lateral movement.

When organizations deploy phishing simulations that mirror these real-world multi-stage attacks, they expose the exact pathways adversaries use to turn a single click into a domain-wide breach.

The Economics of Email-Based Attacks

The business model behind email-delivered malware has been fully industrialized. Malware-as-a-Service (MaaS) platforms sell ransomware, infostealers, and phishing kits on subscription, some for as little as $50 per month, complete with dashboards, customer support, and automatic update cycles that keep payloads ahead of signature-based detection.

A 2024 academic analysis of the MaaS ecosystem documented how these platforms have lowered the barrier to entry to the point where an attacker no longer needs coding skills; they need a credit card and a target list.

Why Email Remains the Path of Least Resistance

Email is the one application every organization must keep open to the outside world. Firewalls and secure web gateways can restrict browsing, block USB ports, and segment internal networks, but email flows inbound by design. Employees are conditioned to open messages, download attachments, and click links to do their jobs. Attackers exploit that behavioral default rather than any technical vulnerability.

Technical controls have improved dramatically. AI-based email filters, DMARC enforcement, and sandboxed attachment scanning catch the majority of commodity spam. They consistently fail, however, against targeted attacks that use zero-day malware, compromised legitimate domains, or social engineering with no technical payload at all, just a carefully worded request to transfer funds or share credentials.

The human brain processes an enormous volume of information daily, and in that cognitive load, a well-timed email impersonating a manager or vendor bypasses every technical defense. Employee training that targets the specific decision points attackers exploit transforms the inbox from an uncontrolled attack surface into a trained detection layer, closing the gap that technology alone cannot patch.

How Malware Delivery Through Email Works

Email malware delivery follows a predictable five-stage chain: attackers research targets, weaponize attachments or links, trick users into opening the payload, establish persistent access on the compromised system, and then move laterally to steal data or deploy ransomware.

Each stage depends on a human action. Understanding how malware delivery through email works at every link in that chain is the prerequisite to building defenses that interrupt the attack before execution completes.

Malware delivered through email attack chain executed by hacker at multiple monitors.

1. The Five Stages of Email Malware Propagation

Email malware does not arrive by accident. Every infection follows a structured attack chain. Breaking that chain at any stage neutralizes the threat; letting all five stages complete is how a single malicious attachment becomes a full organizational breach.

Stage 1: Reconnaissance and Targeting

Attackers begin by gathering open-source intelligence (OSINT) on the target organization and its employees. LinkedIn profiles, corporate organizational charts, earnings call transcripts, and social media activity reveal reporting structures, vendor relationships, and the names of executives and finance staff.

This information shapes the impersonation context: an attacker posing as a CFO can reference a real vendor and a real invoice amount, making the email indistinguishable from legitimate business correspondence.

Stage 2: Delivery and Social Engineering

The weaponized email arrives carrying a malicious attachment. An Excel file with hidden macros, a PDF with an embedded link, a ZIP archive containing a script, or a link to a compromised website hosting a drive-by download.

The social engineering wrapper is what makes it land. The email mimics an urgent invoice, a shared document from a colleague, a failed delivery notice, or a security alert from IT. The Verizon 2026 Data Breach Investigations Report found roughly 62% of breaches involved a human element, with email-based malware delivery remaining the dominant initial access vector.

Stage 3: Initial Execution

Execution requires a user action: opening the attachment, enabling macros, clicking a link, or extracting and running a compressed file. The moment that action occurs, the malware's first-stage payload executes in memory. A lightweight downloader or script runs silently. No splash screen, no error message, no visible indication that anything has happened. The downloader's sole function is to phone home and retrieve the second-stage payload.

Stage 4: Establishing Persistence

Once the full payload deploys, the malware ensures it survives reboots, logoffs, and user sessions. It writes itself into the Windows Registry, creates scheduled tasks, drops files into the startup folder, or manipulates inbox rules in cloud email accounts to maintain covert access. This persistence layer is what transforms a one-time compromise into a long-term foothold, and it is covered in detail later in this section.

Stage 5: Lateral Movement and Data Exfiltration

With persistence locked in, attackers move beyond the initially compromised endpoint. They harvest stored credentials, scan the internal network for file shares and domain controllers, and pivot to higher-value systems. The endpoint that opened the email becomes a bridgehead into the entire organization.

Data exfiltration often begins weeks or months after the initial infection, when the attacker has mapped enough of the environment to extract maximum value. Customer records, intellectual property, and financial documents all leave the network before anyone notices the original compromise.

The five-stage propagation model can be summarized as follows:

Stage Attacker Action Defensive Interruption Point
1. Reconnaissance OSINT gathering on targets Limit public employee data exposure
2. Delivery Weaponized email with attachment or link Advanced email filtering and attachment sandboxing
3. Initial Execution User opens or clicks malicious payload Security awareness training and simulation
4. Persistence Registry modification, scheduled tasks, inbox rules Endpoint detection and response (EDR)
5. Lateral Movement Credential harvesting, network pivoting Network segmentation and least-privilege access

2. From Delivery to Execution: The Infection Chain

The technical sequence between email arrival and full compromise is compressed into seconds. Understanding each link in that chain clarifies where security controls can intervene.

The chain begins the moment the email reaches the recipient's inbox. If the email security gateway does not flag the message, the user sees what appears to be a legitimate message. Attackers continuously test their payloads against common filters to ensure they pass. The attachment or link sits among dozens of other routine emails, indistinguishable from real business.

User interaction triggers the next link. Opening a weaponized Office document and clicking "Enable Content" to view a macro launches the first-stage payload. Clicking a link to a compromised site initiates a drive-by download that exploits browser or plugin vulnerabilities. In either case, the user's action provides the execution context the malware needs.

Payload download or execution follows immediately. The first-stage payload is small, often just a few kilobytes of obfuscated script, designed to bypass signature-based detection. It connects out to an attacker-controlled server and retrieves the second-stage payload: a remote access trojan (RAT), an infostealer, or ransomware. Because the download uses HTTPS on standard ports, it blends into normal web traffic.

The final link in the infection chain is the command-and-control callback. Once the full payload is running, it establishes a connection back to attacker infrastructure. This C2 channel lets the operator issue commands, exfiltrate data, and deploy additional tools. The callback is often disguised as routine DNS queries or traffic to legitimate cloud services, making it difficult for network monitoring tools to distinguish from normal business activity.

3. How Malware Establishes Persistence

Persistence is what separates a fleeting compromise from a sustained intrusion. Once malware achieves initial execution, its next priority is ensuring it remains active across reboots, credential changes, and user sessions. Several techniques achieve this. Sophisticated malware often layers multiple persistence mechanisms simultaneously so that removing one does not evict the attacker.

Registry modification is the most common Windows persistence method. Malware writes entries under HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run or the equivalent HKEY_LOCAL_MACHINE hive hive so that its executable launches automatically at login. More advanced variants use registry keys that are less frequently monitored. Winlogon\Shell, AppInit_DLLs, or service configuration keys achieve the same outcome with lower detection probability.

Scheduled tasks offer another reliable foothold. Attackers create a task configured to run the malware at system startup, at a recurring interval, or upon specific trigger events like user logon. Because Task Scheduler entries are legitimate Windows functionality, they rarely draw attention unless security teams are actively auditing task creation events.

Startup folder placement is simpler but still effective. Dropping a shortcut or executable into the Windows Startup folder ensures the malware runs every time the user logs in. While endpoint detection tools flag this more readily than registry-based persistence, it remains common in commodity malware that prioritizes speed over stealth.

Email forwarding rules and inbox rule manipulation are the persistence vector unique to cloud email compromise. Once an attacker gains access to a Microsoft 365 or Google Workspace account, hidden inbox rules can forward sensitive messages to an external address, delete security alerts before the user sees them, or archive copies of all communications. These rules survive password resets: the credential changes, but the rule persists until an administrator explicitly removes it.

Each persistence mechanism exploits a different blind spot: the endpoint, the task scheduler, the file system, or the cloud mailbox. Organizations that monitor only one of these surfaces leave attackers with multiple paths back in. Effective defense requires continuous visibility across all of them, paired with phishing simulations that train employees to stop malware at Stage 2, before delivery ever becomes execution.

Primary Methods Attackers Use to Deliver Malware via Email

Malware reaches organizations through email via three distinct delivery channels, each exploiting a different gap in the security stack. Attachments execute code directly on the target machine the moment a file opens. Link-based delivery redirects victims to external infrastructure the email gateway never inspects. Multi-stage approaches use email only as the opening move, inserting credential theft as an intermediate step that makes the final payload nearly indistinguishable from legitimate authentication.

In practice, these methods rarely operate in isolation. Modern campaigns layer attachments, links, and social engineering into blended attacks that demand defenses spanning all three vectors simultaneously.

How Do Malicious Attachments Deliver Malware?

Attachment-based malware represented just 5% to 6% of email attacks in Q1 2026, according to Microsoft threat intelligence analyzed by Cybersecurity Dive, a sharp decline from earlier years. Yet the absolute volume remains dangerous. In 2025, users encountered over 144 million malicious and potentially unwanted email attachments, a 15% increase from the previous year, according to Kaspersky telemetry.

The mechanics are straightforward. An attachment executes code locally the moment a user opens the file, bypassing network-layer defenses that might block a malicious URL. Attackers disguise executables with double extensions: a file named invoice.pdf.exe appears as invoice.pdf on systems that hide known extensions, tricking the recipient into believing they are opening a document.

Embedded scripts inside legitimate-looking Office files pose a similar risk. A Word document with a malicious macro downloads a payload from a command-and-control server once the user clicks "Enable Content."

The critical distinction between attachment-based and link-based delivery turns on where the malicious logic executes. An attachment brings the threat inside the perimeter immediately, running code on the target's machine. A link keeps the threat at arm's length.

The payload lives on an external server and only reaches the endpoint after a series of redirects. This makes attachments riskier for attackers in one sense: they must bypass the email gateway's signature-based and heuristic scanning.

For defenders, the cost is higher. An attachment that clears the gateway gives security teams zero additional chances to detect it, while a link-based attack creates telemetry at every hop.

How Does URL-Based Malware Delivery Work?

Embedded links are now the dominant delivery mechanism for email-borne threats, and the technique has evolved well beyond simple phishing pages. Instead of attaching a malicious file, attackers direct recipients to an external URL that either delivers malware through a drive-by download or harvests credentials as a prerequisite for deeper compromise.

The drive-by download exploits browser or plugin vulnerabilities the moment a victim lands on the page. No click beyond the initial link is required. The page loads, a script executes, and malware installs silently. Credential-harvesting pages take a more patient approach, impersonating a trusted service like Microsoft 365 or Google Workspace to capture login details.

Attackers then use those credentials to access the victim's real account, read email threads, and launch internal phishing campaigns that bypass external gateway scanning entirely.

What makes URL-based delivery difficult to stop is the abuse of legitimate cloud infrastructure. Attackers host malicious files on OneDrive, SharePoint, and Google Drive, then email links that point to these trusted domains. Because the domains themselves are benign and widely used, most organizations cannot block them without disrupting business operations.

The link passes through the email security gateway without triggering reputation-based filters, and the victim sees a familiar interface that lowers suspicion. Downloading and opening the file then bypasses the email scanning layer completely.

What Are Multi-Stage and Hybrid Malware Delivery Approaches?

The most dangerous email-based malware campaigns today rarely rely on a single delivery technique. Multi-stage attacks chain together credential theft, lateral movement, and eventual payload deployment, using email as merely the entry point into a broader intrusion. The email itself may contain nothing obviously malicious, only a socially engineered prompt that sets the victim on a path toward compromise.

Calendar invite exploitation has reemerged as an effective vector. Attackers send .ics file attachments or calendar invitations that, when accepted, populate the victim's calendar with an event containing a malicious link or attachment. Because calendar invites originate from platforms users trust and often bypass traditional email scanning pipelines, they achieve open rates far higher than standard phishing emails.

Kaspersky's 2025 spam and phishing analysis noted that calendar-based phishing, which originated in the late 2010s, resurfaced in 2025 with a renewed focus on corporate users, exploiting the routine acceptance of meeting invitations to slip past defenses.

QR code attacks sidestep link-based detection entirely. Instead of embedding a clickable URL, attackers place a QR code in the email body or a PDF attachment. The victim scans the code with a mobile device, which opens the malicious link outside the corporate security stack.

No URL exists for the email gateway to scan, no domain reputation check fires, and often no endpoint protection covers the personal phone. QR-code phishing surged 146% in the first quarter of 2026, jumping from 7.6 million threats in January to 18.7 million in March and becoming the fastest-growing attack vector of the quarter, according to an analysis of Microsoft threat intelligence.

The distinction between mass spam campaigns and targeted spear-phishing delivery also shapes how these techniques are deployed. Mass campaigns use attachments and generic links at high volume, relying on statistical probability. Send 100,000 emails and even a 0.1% success rate yields 100 compromised endpoints.

Spear-phishing delivery uses open-source intelligence (OSINT) to personalize every element: the sender name matches a real colleague, the attachment references an actual project, and the link points to a credential-harvesting page that mimics the specific single sign-on portal the target organization uses.

Where mass campaigns cast a wide net, spear-phishing aims at specific individuals. Finance approvers, IT administrators, and executive assistants hold credentials that unlock far more than a single endpoint.

Organizations that train employees to recognize these blended delivery patterns across realistic phishing simulations reduce the probability that any single technique succeeds. Properly trained users question the request itself rather than trying to classify the delivery mechanism in the moment.

File Types and Extensions That Conceal Email Malware

Email attackers rely on a predictable set of file types to deliver malware. Windows executable files (.exe) accounted for 54% of malware file type detections via the web in 2024, according to Statista, making them the single most weaponized format in circulation. Archive formats, script files, and disk images each introduce their own bypass mechanisms that evade both automated scanning and human judgment.

High-Risk File Extensions

Executable and script-based file types remain the most dangerous attachments an employee can encounter. These formats either run code directly or invoke system interpreters capable of executing arbitrary commands.

  • .exe, Windows executable files. These launch immediately on double-click and represent the dominant malware delivery format, with 54% of global web-based malware detections attributed to this extension in 2024.
  • .scr, Screensaver files. Functionally identical to .exe files but disguised as benign display programs, often slipping past legacy attachment filters that blocked executables but permitted screensavers.
  • .bat and .cmd, Windows batch scripts. Text files containing sequences of system commands that execute with the privileges of the user who runs them. A single line can download and launch a remote payload.
  • .ps1, PowerShell scripts. PowerShell provides deep system access, and a malicious .ps1 can download staged payloads, disable security tools, and establish persistence without dropping a traditional executable.
  • .vbs, VBScript files. Lightweight and still natively executable on Windows, .vbs files have powered attack chains from ILOVEYOU in 2000 to modern ransomware delivery.
  • .js, JavaScript files. When executed outside the browser by the Windows Script Host, .js attachments gain filesystem access that browser-based JavaScript never has.
  • .jar, Java archive files. These execute via the Java Runtime Environment if installed, running cross-platform and bypassing Windows-specific security controls.
  • .lnk, Windows shortcut files. A .lnk file points to a legitimate system binary while passing malicious arguments, letting attackers execute code without embedding malware in the shortcut itself.
  • .wsf, Windows Script Files. These combine multiple scripting languages into a single file, splitting malicious logic across script engines to evade detection.
  • .hta, HTML Application files. Executed by the Microsoft HTML Application Host, .hta files run with full system privileges outside the browser sandbox, making them a preferred initial access vector for advanced threat actors.

Archive Formats and Password Protection

Archive files conceal malware through compression, encryption, and structural nesting that defeats signature-based scanning. The formats most frequently weaponized include .zip, .rar, .7z, .tar, and .gz. Each bundles files into a container that scanners cannot inspect without unpacking, and many email security gateways skip deep archive inspection under load.

Password-protected archives multiply the evasion advantage. When a .zip or .7z file is encrypted, automated scanners cannot peer inside because the content is opaque until decrypted. Attackers supply the password in the email body. "Your invoice is attached, password: 1234" is trivial for a human recipient but an insurmountable barrier for most security tools.

This technique has surged among ransomware affiliates and initial access brokers who know that a simple password wrapper defeats a surprising percentage of perimeter defenses.

The .img and .iso disk image formats introduce a structural problem: the Mark-of-the-Web (MoTW) propagation gap. When Windows extracts files from a .zip using its built-in utility, it applies the MoTW flag, an NTFS alternate data stream that tells Windows the file came from the internet and should open in Protected View.

Third-party tools like 7-Zip historically failed to propagate this flag. A zero-day vulnerability in 7-Zip (CVE-2025-0411), patched in January 2025, allowed attackers to craft nested archives that stripped MoTW entirely, letting malicious files extracted from .iso and .img containers execute without security warnings. Russian cybercrime groups exploited this flaw to deliver SmokeLoader malware against Ukrainian targets through phishing campaigns.

How Attackers Obfuscate File Types

Beyond choosing dangerous extensions, attackers actively manipulate how file types appear to recipients. The most common technique is the double extension: a file named invoice.pdf.exe exploits Windows' default setting to hide known extensions, so the user sees only invoice.pdf and opens what they believe is a document. The trailing .exe executes.

Misleading MIME types compound this deception. Email clients display attachments based on the declared MIME type in the message header rather than the actual file content. An attacker can declare application/pdf while attaching an executable, and the email client will render a PDF icon regardless of what the file actually contains.

Icon spoofing takes visual deception further. Attackers embed legitimate-looking document or folder icons into executable files using resource editors. An .exe with a Microsoft Word icon sitting in a downloads folder is functionally indistinguishable from a real document at a glance.

On macOS, .app bundles and .dmg disk images can be crafted with custom icons that mirror legitimate software installers. No major operating system reliably surfaces true file identity without deliberate user configuration: Windows hides extensions by default, macOS relies on Uniform Type Identifiers rather than extensions for file association, and Linux desktop environments trust MIME detection that attackers manipulate through carefully crafted magic bytes.

File Extension Risk Comparison

Extension Category Risk Level Primary Threat
.exe Executable Critical Direct code execution on open
.scr Executable Critical Functionally identical to .exe
.hta Script/Application Critical Unsandboxed system access
.ps1 Script Critical PowerShell-based payload staging
.vbs Script High Legacy script execution persistence
.js Script High Filesystem access via Windows Script Host
.bat / .cmd Script High Command-line payload download
.wsf Script High Multi-engine script obfuscation
.jar Archive/Executable High Cross-platform Java execution
.lnk Shortcut High Argument injection via system binaries
.zip / .rar / .7z (password-protected) Archive High Scanner-evading encrypted payloads
.iso / .img Disk Image High MoTW bypass on extraction
.zip / .rar / .7z (unprotected) Archive Medium Nested malicious content
.tar / .gz Archive Medium Unix-focused payload bundling

Knowing which extensions carry the highest risk is foundational, but recognition without conditioned response leaves organizations exposed. Phishing simulations that test employees against the exact attachment-based attack patterns described here turn static knowledge into verifiable defensive behavior.

Types of Malware Delivered Through Email

Email remains the dominant delivery mechanism for virtually every category of malicious software. The Anti-Phishing Working Group (APWG) recorded 1,003,924 phishing attacks in the first quarter of 2025, the highest volume since late 2023, while the FBI Internet Crime Complaint Center received more than 191,000 phishing and spoofing complaints in 2025.

Understanding the distinct families of email-borne malware determines which detection tools an organization deploys, which employee behaviors it trains for, and how fast its incident response team must move when a threat lands.

Ransomware, trojans, and self-replicating worms each pursue fundamentally different objectives once they breach the inbox, and that difference shapes everything from dwell time to remediation cost. Ransomware operators prioritize speed and visibility: they want encryption running within hours so the extortion demand lands while panic is high.

Trojans and remote access tools (RATs) are designed for stealth, often lingering for months while attackers map networks, escalate privileges, and exfiltrate data before anyone notices. Worms, bots, and fileless malware introduce a third dimension: autonomous propagation and resource hijacking that can conscript a device into a criminal infrastructure without the victim ever seeing a ransom note or a suspicious login alert.

All three categories share the same entry point: a single employee opening an attachment or clicking a link. The divergence in tactics, dwell time, and business impact still makes it essential for security teams to treat them as distinct threats requiring layered countermeasures.

Malware delivered through email resulting in ransomware file encryption warning.

Ransomware: Encryption, Extortion, and the RaaS Economy

Ransomware is email's most expensive payload. The modern ransomware ecosystem operates on a franchise model called ransomware-as-a-service (RaaS), where specialized developers build and maintain the encryption tools while affiliate operators handle distribution, often through phishing campaigns, and split the proceeds.

The UK's National Crime Agency revealed that the LockBit group alone launched more than 7,000 attacks globally between June 2022 and February 2024 before its leader was unmasked. After LockBit's disruption, groups including RansomHub and Qilin rapidly scaled operations. Qilin alone hit 74 victims in April 2025, according to Cyble.

Email-delivered ransomware follows well-documented infection chains. The Ryuk ransomware, one of the most destructive families in history, reached victims through a multi-stage payload sequence: a phishing email delivered the Emotet trojan, which downloaded the TrickBot banking trojan, which in turn deployed Ryuk after determining the target was worth ransoming.

Other email-borne families include Petya, which overwrites the master boot record rather than individual files, and Maze, which pioneered the double-extortion model. That dual-threat tactic, encrypt files locally while exfiltrating sensitive data to a criminal server, gives attackers two pressure points. Even organizations with robust backups face the threat of public data exposure if they refuse to pay.

The encryption-extortion combination transforms a malware infection from an IT recovery problem into a legal, regulatory, and reputational crisis. Ransomware groups now operate dedicated leak sites, publish samples of stolen data to prove access, and give victims countdown timers that accelerate pressure on leadership.

Trojans and Remote Access Tools: Stealth, Theft, and Long Dwell Times

Trojans and RATs differ from ransomware in a critical respect: their objective is sustained, covert access rather than immediate disruption. Where ransomware announces itself within hours, a banking trojan or RAT may operate undetected for months, siphoning credentials, intercepting financial transactions, and exfiltrating intellectual property.

Banking trojans like Emotet, originally detected in 2014 as a credential-stealing tool, evolved into modular delivery platforms that drop additional payloads based on what the attacker discovers about the compromised environment. Emotet's main distribution method remains phishing emails containing malicious Microsoft Office documents with embedded macros. Once executed, the macro downloads the payload and the trojan begins harvesting browser credentials, email account passwords, and financial data.

RATs take this intrusion model further by giving attackers real-time control over infected machines. Unlike ransomware, which burns its access path with encryption, RAT operators preserve and deepen their foothold. The dwell time difference is stark.

Ransomware operators may move from initial access to encryption within a single workday, while RAT infections can persist for months before detection.

Targeted espionage intrusions routinely exceed that figure by wide margins. This extended window lets attackers study organizational hierarchies, identify high-value targets, and time their most damaging actions, whether that means wiring fraudulent payments or selling access to a ransomware affiliate.

Worms, Bots, Fileless Malware, and Social Engineering Variants

Beyond the ransomware-trojan binary, email delivers a broader ecosystem of self-propagating and stealth-resident threats. Self-replicating worms spread laterally without user interaction once inside the network, exploiting unpatched vulnerabilities to multiply across connected machines. Spambots take a different approach: after infecting a host through email, they harvest the victim's address book and use the compromised account to send malicious messages to every contact, turning a single infection into a distribution engine.

Botnet recruitment via email transformed the Mirai malware from a niche IoT threat into infrastructure-scale disruption. While Mirai itself primarily spreads by scanning for vulnerable IoT devices, its successors and variants have incorporated phishing as an initial access vector, conscripting compromised machines into botnets used for distributed denial-of-service attacks, credential stuffing, and cryptomining.

Fileless malware represents the stealthiest category. It never writes a file to disk, residing entirely in memory or within legitimate system processes like PowerShell or Windows Management Instrumentation. Because traditional signature-based antivirus scans for files, fileless attacks bypass these tools entirely.

Keyloggers, rootkits, spyware, and adware all fall within this spectrum of email-delivered threats that prioritize persistence and data capture over destruction. Phishing simulations that test employees against the full range of these delivery tactics give security teams visibility into which attack types their workforce is most vulnerable to before a real payload arrives.

Resident viruses embed themselves in system memory and infect files as they are opened. Multipartite viruses combine characteristics of file infectors and boot sector viruses, making them harder to fully eradicate. At the far end of the spectrum, virus hoaxes use pure social engineering: a warning email claiming the recipient's system is infected, urging them to delete a legitimate system file or download a "fix" that is itself malicious.

Each variant exploits a different facet of trust, and each enters through the same vector: an email an employee decided to open.

Malware Types Delivered Through Email: Comparison Table

Malware Type Primary Delivery Method via Email Primary Impact Real-World Examples
Ransomware (RaaS) Malicious attachments (Office docs, ZIP archives), embedded links to download payloads File encryption, data exfiltration, extortion LockBit, RansomHub, Qilin, Petya, Maze, Ryuk (via Emotet/TrickBot)
Banking Trojans Macro-enabled Office documents, downloader links Credential theft, financial fraud, secondary payload delivery Emotet, TrickBot, Ursnif, Dridex
RATs Phishing links to malicious executables, weaponized attachments Remote system control, lateral movement, data exfiltration njRAT, AsyncRAT, Agent Tesla
Worms Infected email attachments that self-execute or exploit vulnerabilities Network-wide propagation, resource consumption Mydoom (email worm), ILOVEYOU
Bots / Botnets Malicious links, infected attachments, social engineering lures Device conscription into criminal infrastructure, DDoS attacks Mirai variants, Emotet-spread botnets
Fileless Malware Links to malicious scripts, macro-laden documents invoking PowerShell Memory-resident execution, credential harvesting, evasion of traditional AV PowerShell Empire, Kovter, Poweliks
Keyloggers / Spyware Attachments posing as legitimate software, phishing links Keystroke capture, screen monitoring, credential theft HawkEye, Agent Tesla
Virus Hoaxes Pure social engineering, no actual malware payload Deletion of legitimate system files, installation of fake "antivirus" tools SULFNBK.EXE hoax, jdbgmgr.exe hoax

Email-borne malware spans a spectrum from immediate destruction to silent surveillance, but every variant on this table exploits the same vulnerability: a human being making a split-second decision about what to open. Training employees to recognize malicious indicators across all these delivery mechanisms transforms the inbox from a perimeter that attackers expect to breach into one where every opened attachment is preceded by a moment of informed judgment.

Social Engineering and Impersonation Tactics in Malware Emails

Social engineering succeeds in email malware delivery because attackers exploit cognitive reflexes that operate faster than rational evaluation: urgency, deference to authority, and trust in familiar brands. Check Point Research found in Q4 2025 that Microsoft alone accounted for 22% of all brand phishing attempts, confirming that impersonation of trusted platforms has become the primary vector for how malware is delivered through email.

Security-conscious employees who would never click a suspicious link will comply with what appears to be a routine Microsoft 365 login alert, because the psychological trigger overrides the technical warning signs.

Common Social Engineering Tactics in Malware Emails

Every malware-laden email relies on at least one psychological lever to short-circuit the recipient's skepticism. Attackers do not need to defeat an email filter if they can convince the target to open the attachment themselves.

Urgency and fear triggers are the most common and consistently effective. An email warning that "unusual sign-in activity was detected on your account, verify within 24 hours or access will be suspended" triggers a fear response before the recipient has time to evaluate the message.

The recipient clicks the malicious link because the perceived cost of inaction feels immediate and catastrophic. Ransomware delivery campaigns frequently exploit this trigger: an invoice marked "OVERDUE, remit payment or service terminates today" arrives with an infected attachment, and the finance employee acts to avert a business disruption that does not exist.

Authority impersonation weaponizes organizational hierarchy. An email that appears to come from the CEO asking a finance team member to "review the attached contract before our 3 p.m. call" carries the weight of a direct command. The sender name reads "Sarah Chen, Chief Financial Officer," the tone is curt and decisive, and the attachment is labeled "Q4FinancialReview.xlsm."

The employee has been conditioned to respond promptly to executive requests, and that conditioning is precisely what the attacker exploits. The same deference-to-authority reflex drove the 2024 incident in which an Arup finance employee approved a $25.6 million transfer after joining a video call populated entirely by deepfakes of company executives. The psychological mechanism is identical, scaled from email attachment to multi-channel impersonation.

Curiosity gaps provoke an almost involuntary click. Subject lines like "Your termination paperwork is attached," "Re: the complaint filed against you," or "Photos from the company event, you're in these" exploit the human need to resolve ambiguity. The payload, often an information-stealing trojan or keylogger, activates the moment the attachment is opened. Attackers count on the fact that uncertainty is psychologically uncomfortable and clicking feels like resolving it.

Social proof and familiarity exploitation embed the recipient in a believable social context. An email that reads "Following up on our conversation with Jennifer from procurement, she suggested I send the updated vendor forms directly to you" fabricates a shared reference point.

If Jennifer really works in procurement and the recipient recently engaged with that department, the email passes every internal coherence check. The malware, disguised as a shared document link, spreads through precisely this kind of contextual camouflage.

Scarcity rounds out the psychological toolkit. "Only 2 seats remain at this price, register now" or "Your cloud storage is 99% full, upgrade immediately to avoid data loss" creates artificial time pressure. The recipient acts to secure a perceived benefit or avert a threatened loss and, in doing so, opens the door for the payload.

Brand Impersonation and Domain Spoofing

Brand impersonation transforms malware delivery from a generic high volume attack into something indistinguishable from the services employees use every day. Check Point Research's Q4 2025 Brand Phishing Report ranked Microsoft (22%), Google (13%), and Amazon (9%) as the three most impersonated brands globally, with Apple (8%) and Facebook (3%) following.

The technology sector dominated brand impersonation campaigns, reflecting attackers' focus on credentials that unlock enterprise access, cloud services, and identity platforms.

A Microsoft 365 credential-harvesting email is the archetype. It arrives styled identically to a legitimate Microsoft notification: same logo, same typeface, same "protect your account" language, directing the recipient to a login portal that mirrors the real thing pixel for pixel.

The employee enters their credentials, the attacker captures them, and now the attacker has authenticated access to the organization's email environment. From there, malware deployment to colleagues across the address book becomes a single step.

Amazon delivery confirmation scams spike during holiday shopping seasons when volume noise is highest. An email claims a package could not be delivered and asks the recipient to "confirm shipping details" via a link that downloads a remote access trojan.

The subject line mimics the exact format Amazon uses, right down to the fake order number. Bank security notices follow the same pattern: an email bearing a financial institution's logo warns of "suspicious wire activity" and demands immediate verification, leading to either a credential-harvesting page or a drive-by download of banking malware.

Lookalike domains and display name spoofing are the technical enablers. A domain like "micros0ft-support.com," with a zero in place of the 'o,' or "amaz0n-delivery.net" passes casual inspection, particularly on a mobile screen where the full URL is truncated.

Display name spoofing is simpler still: the attacker configures the "From" name to read "Microsoft Security Team" while the actual sending address is an unaffiliated free email account. Mobile email clients, which often show only the display name by default, make this tactic especially effective.

Legitimate link mixing defeats URL reputation checks. The email body contains several genuine links to Microsoft's actual support pages or Amazon's real help center, establishing a clean reputation score with automated scanners. The call-to-action button, "Sign In to Review Activity," points to the credential-harvesting page.

Automated systems see a mix of legitimate and suspicious URLs and default to allowing the message through. The human eye sees only the familiar branding and acts accordingly.

The Relationship Between Phishing Campaigns and Malware Delivery

Phishing is the delivery mechanism. Malware, ransomware, information stealers, remote access trojans, banking trojans, is the payload. Conflating the two leads organizations to invest heavily in malware detection while underinvesting in the human-layer defenses that prevent the delivery from succeeding in the first place.

The most damaging attacks chain credential harvesting and malware deployment together in a single continuous campaign. A phishing email directs the recipient to a spoofed Microsoft 365 login page. The attacker captures the credentials, logs into the real account, and conducts reconnaissance: contact lists, email histories, shared files, Teams conversations.

Within hours, the attacker sends a second email from the compromised internal account to colleagues in finance or IT, with a malicious attachment labeled "Invoice_Resubmission.pdf.iso." Because the message originates from a trusted internal sender, it clears both technical filters and human skepticism simultaneously.

This is lateral phishing, and it weaponizes internal trust at scale. The attack needs no technical sophistication when it arrives from a real email address the recipient has exchanged messages with for years. One employee's momentary lapse in a credential-harvesting scheme becomes the launchpad for organization-wide malware distribution.

Organizations that train employees to recognize these chained attack patterns, from brand-impersonation credential harvest to lateral malware spread, break the delivery mechanism before the payload ever lands.

Modern phishing simulations that recreate multi-stage attack chains give employees the lived experience of how one click cascades into organizational compromise, replacing reflexive compliance with recognition under pressure. That recognition hinges on understanding exactly how attackers engineer those clicks in the first place.

How Malicious Attachments, Macros, and Archives Deliver Malware Through Email

Understanding how email-delivered malware breaches systems requires tracing three distinct infection chains. The first is macro-laced Office documents that execute VBA code the moment a user clicks "Enable Content." The second is script-based exploits embedded inside PDFs and other routine file types. The third is archive containers engineered to bypass email security gateways through nesting, encryption, or exotic formatting.

Each mechanism exploits a specific gap in either security tooling or human judgment. Defenders who map all three attack paths can close the most common malware entry points before a single payload detonates.

1. Understand Macro-Based Attacks in Office Documents

Macro-based attacks rely on a single social engineering trick that has worked for decades: convincing the recipient to click "Enable Content." When a user opens a malicious Word or Excel document downloaded from the internet, the file opens in Protected View, a read-only mode that blocks embedded VBA (Visual Basic for Applications) macros from executing. The attacker's entire infection chain depends on the user overriding that protection.

Once enabled, VBA macros execute arbitrary code through a series of staged commands. The macro typically spawns PowerShell or Windows Command Processor with hidden window flags, downloads a second-stage payload from a command-and-control server, and writes it to disk for execution.

That changed abruptly when Microsoft tightened Mark-of-the-Web (MotW) enforcement. Files downloaded from the internet now carry a Zone.Identifier alternate data stream that blocks macros by default, disabling the "Enable Content" button entirely in many cases.

The result was dramatic: malicious Office files collapsed from nearly 50% of all malicious attachments in 2022 to just 2% in 2023. Threat actors did not stop attacking. They migrated to the next available infection vector.

2. Recognize Exploit-Based and Script-Based Infections

With macros locked down, attackers pivoted to script-based infection chains embedded in other file formats. PDF files became a primary vehicle: malicious JavaScript concealed inside PDFs can exploit vulnerabilities in the PDF reader itself to execute shellcode or launch system utilities without any user confirmation. Unlike macros, these exploits do not require the victim to click "Enable Content." The document simply needs to be opened by an unpatched reader.

PowerShell, WScript, and MSHTA are the workhorses of modern script-based delivery. A weaponized PDF or HTML attachment often contains an encoded PowerShell command that downloads and executes a payload in memory, bypassing disk-based antivirus scanning entirely.

WScript executes VBScript or JavaScript files dropped alongside the document. MSHTA, a legitimate Microsoft utility designed to run HTML applications, is frequently abused to fetch and execute malicious HTA files from remote servers. These utilities are signed by Microsoft, meaning endpoint detection tools often whitelist them by default.

Attackers embed obfuscated JavaScript directly into HTML attachments that, when opened in a browser, reconstruct and deliver the payload without any Office dependency. The infrastructure is different, but the outcome is identical: a remote access trojan or information stealer lands on the endpoint, and the attacker gains persistence.

3. Identify How Archive Files Bypass Security Filters

Archive files represent the most persistent evasion technique in the attacker toolkit because they exploit fundamental limitations in how email security gateways inspect content. Signature-based scanning matches known malware hashes against incoming files, so an attacker who compresses a payload into a .zip, .rar, or .7z archive changes the file hash entirely.

Even heuristic analysis struggles when archives are nested several layers deep or protected with a password, since the scanning engine cannot decrypt and inspect the inner contents.

Password-protected archives are especially effective. The password is typically included in the email body. "Your invoice is attached, password: 2026." Automated scanners rarely correlate body text with attachment decryption at line speed. Nested archives compound the problem: a .zip inside a .zip inside a .tar file forces the gateway to recursively unpack each layer, and most appliances impose recursion depth limits to avoid denial-of-service conditions. Attackers exceed those limits deliberately.

Disk image formats such as .img and .iso introduce a subtler vulnerability. These files propagate Mark-of-the-Web inconsistently depending on which extraction tool the user employs. Some archivers apply MotW to extracted contents correctly. Others omit it entirely, meaning malware extracted from an .iso file can execute without triggering Windows' standard download warning.

Kaspersky's 2025 analysis of archive-based attack techniques documents multiple CVEs where archiver flaws allowed attackers to strip MotW from extracted files entirely, including CVE-2025-0411 in 7-Zip, CVE-2025-31334 in WinRAR, and CVE-2024-8811 in WinZip. An employee who extracts an .iso attachment with a vulnerable archiver sees no security prompt before double-clicking the executable inside. The entire defense evaporates at the extraction layer.

Closing these entry points demands more than gateway policies. It requires a workforce trained to recognize weaponized attachments across every format attackers use before anyone clicks "Enable Content" or unpacks a file.

What Happens After Infection: Lateral Spread, Persistence, and Warning Signs

Once malware delivered through email executes on a single endpoint, the initial foothold can trigger lateral movement across the network in as little as 4 minutes, according to ReliaQuest's 2026 threat analysis. Attackers pivot through harvested credentials, open SMB shares, and hijacked remote desktop sessions, then establish persistence through hidden inbox rules and registry modifications.

Global median dwell time has climbed to 14 days, according to Mandiant's M-Trends 2026 report, meaning by the time most organizations detect the intrusion, the attacker has typically exfiltrated data, compromised multiple accounts, and positioned ransomware for deployment across critical systems.

Malware delivered through email detected by security operations center analysts.

Lateral Movement Across the Network

A single infected workstation is rarely the attacker's end goal. Once the initial malware, often an infostealer or a remote access trojan delivered through a phishing attachment, establishes a foothold, the operator begins mapping the network for high-value targets. The playbook is methodical: harvest credentials from the compromised machine's memory and local storage, enumerate active directory objects, scan for open Server Message Block (SMB) shares, and pivot.

Pass-the-hash techniques allow attackers to authenticate to additional systems without ever cracking a plaintext password. By extracting NTLM hashes from the compromised host's LSASS process memory, the attacker authenticates laterally as the original user, no password required.

Remote Desktop Protocol (RDP) hijacking compounds the damage: if the initial victim has active RDP sessions to servers or other workstations, the attacker tunnels through those connections to reach deeper segments of the environment.

The velocity of this stage has accelerated sharply. Mandiant's M-Trends 2026 report documented attackers handing off initial access to specialized operators in a median of 22 seconds. ReliaQuest researchers observed lateral movement in as little as 4 minutes in 2025, with the fastest data exfiltration completing in 6 minutes.

The same Mandiant report found that organizations self-detecting intrusions did so in a median of 9 days. Those relying on external notification, such as law enforcement, a third-party alert, or a ransomware note, took a median of 25 days to confirm the breach. That gap represents weeks of unchecked lateral movement, privilege escalation, and data staging.

Persistence Mechanisms and Email Rule Manipulation

Lateral access is valuable only if the attacker can keep it. Persistence mechanisms ensure that reboots, password resets, and even endpoint re-imaging do not evict the adversary entirely. Attackers commonly deploy scheduled tasks, registry run keys, and malicious services that re-establish the connection to command-and-control infrastructure every time a machine restarts. On domain controllers, they create shadow admin accounts or modify group policy objects to push their tooling organization-wide.

One of the most overlooked persistence tactics is inbox rule manipulation. Once an attacker compromises a Microsoft 365 or Google Workspace account, often using credentials harvested by the initial email-delivered malware, hidden forwarding rules can silently redirect copies of all incoming and outgoing mail to an external address.

These rules survive password changes because they exist at the mailbox level rather than the authentication layer. The attacker reads sensitive correspondence for weeks, harvesting financial data, legal documents, and merger-and-acquisition intelligence without triggering a single alert.

Compromised accounts also become launchpads for further attacks. The attacker weaponizes the victim's own address book, sending malware-laced replies to existing conversation threads. A recipient who trusts a colleague's email address is far more likely to open an attachment than one who receives a cold message from an unknown sender.

This is how a single email-delivered infection inside a finance department escalates into a supply-chain compromise that reaches clients, partners, and vendors. Multi-channel phishing simulations help security teams train employees to recognize these internally propagated threats before they trigger a cascade of downstream infections.

Warning Signs of Infection

Detecting a post-infection active intrusion requires looking beyond antivirus alerts. Attackers operating with stolen credentials and living-off-the-land binaries often generate no signature-based detection at all. The symptoms are behavioral, and they show up at the endpoint, the mailbox, and the session layer simultaneously.

The table below maps observable warning signs to the malware categories that most commonly produce them. Any single symptom warrants investigation. Two or more appearing together on the same machine or user account signal a probable active compromise.

Warning Sign Likely Malware Type
Unexpected system slowdowns, fans running at full speed Cryptomining malware, botnet agents
Unexplained file changes, renamed directories, or file encryption Ransomware, wiper variants
Random application launches, cursor movement, or windows opening Remote access trojans (RATs), fileless malware
Rapid unexplained loss of free storage space Cryptominers, data exfiltration tools
Suspicious pop-ups, fake antivirus alerts, or browser redirects Adware, scareware, browser hijackers
Frequent blue screens or unexpected application crashes Rootkits, kernel-level malware drivers
Inbox rules forwarding mail to unknown external addresses BEC operators, infostealer-fueled account takeover
Unrecognized active sessions in account security logs Credential theft, session token hijacking

The final two indicators, unauthorized forwarding rules and unrecognized sessions, are particularly urgent because they confirm that the attacker has moved beyond the endpoint and now operates inside the organization's cloud tenant. Revoking sessions and resetting credentials is necessary but insufficient: the mailbox rules must be audited and purged, or the attacker retains read access regardless of password changes.

Real-World Email Malware Attacks and Case Studies

The anatomy of email-delivered malware is best understood through documented breaches that reveal exactly how attackers exploit human trust at the inbox. From a phishing operation that spanned continents to a ransomware attack that hijacked a rail operator's own email system to taunt employees, the case studies below expose recurring patterns that technical controls alone consistently fail to stop.

Notable Email Malware Campaigns

Operation Phish Phry (2009) stands as one of the largest cyber fraud phishing cases ever prosecuted. Egyptian-based attackers sent meticulously crafted emails impersonating legitimate U.S. financial institutions to American bank customers. When recipients entered their credentials on the fraudulent websites, attackers harvested usernames, passwords, and account details, then routed approximately $1.5 million through mule accounts in California, Nevada, and North Carolina.

The FBI-led investigation resulted in charges against nearly 100 individuals across both countries in what then-Director Robert Mueller described as a "cyber arms race." Operation Phish Phry demonstrated that email-based fraud did not require sophisticated code. It required only a convincing sender name, a spoofed bank domain, and enough recipients to guarantee someone would click.

The Merseyrail ransomware attack (2021) brought the threat closer to critical infrastructure. Attackers from the LockBit group compromised a privileged Office 365 account at the UK rail operator, likely through a spear phishing email that harvested the credentials of Managing Director Andy Heath.

Once inside, the attackers deployed ransomware across Merseyrail's systems and then used Heath's own email account to message employees and journalists, attaching stolen employee personal data as proof of the breach. Computer Weekly reported that the attack exploited the compromised Office 365 account to execute the intrusion, demonstrating how a single successful credential phishing email can cascade into full organizational compromise.

Widespread Microsoft 365 credential phishing (2021) surged as remote work expanded the attack surface. Campaigns used fake Microsoft login pages delivered through email links that appeared to originate from colleagues or IT support. Once credentials were captured, attackers established persistent access to corporate mailboxes, searched for financial conversations, and launched business email compromise (BEC) attacks from inside trusted domains.

The FBI's Internet Crime Complaint Center (IC3) reported that BEC accounted for $3 billion in losses in 2025, much of it originating from credential harvesting operations that begin with a single malicious email.

Ransomware Families Delivered via Email

Many of the most destructive ransomware strains began their attack chain with an email attachment. Petya first surfaced in 2016 through phishing emails carrying malicious Dropbox links that, when opened, executed a macro-laden document. The malware overwrote the master boot record, rendering entire systems unusable until a ransom was paid.

Maze pushed the model further by pioneering double extortion. It arrived via spear phishing attachments, encrypted files, and simultaneously exfiltrated data to pressure victims into paying. REvil (Sodinokibi) affiliates routinely initiated attacks through spear phishing emails with malicious attachments or links to remote payloads, targeting managed service providers and large enterprises alike.

The most operationally sophisticated delivery chain belonged to Ryuk, which rarely arrived alone. The Emotet trojan, itself distributed through phishing emails carrying weaponized Microsoft Office documents with malicious macros, served as the initial loader.

Once Emotet established a foothold, it downloaded TrickBot, a modular banking trojan that harvested credentials, performed reconnaissance, and moved laterally across the network. TrickBot then determined whether the victim qualified as a high-value target. If so, it delivered the Ryuk ransomware payload, which encrypted files across the domain. This multi-stage, email-initiated pipeline allowed attackers to selectively ransom organizations that could pay the highest demands.

Lessons Learned from High-Profile Breaches

A clear pattern cuts across every case: technical controls at the email gateway were insufficient because the attacks exploited human decision-making rather than software vulnerabilities. In Operation Phish Phry, no firewall or antivirus could prevent a user from typing credentials into a fake bank portal. In the Merseyrail attack, multifactor authentication gaps or token theft meant the phishing email's success was the breach itself.

Organizations repeatedly missed warning signs. Abnormal login locations, unusual mailbox forwarding rules, and suspicious attachment execution went undetected for days or weeks. Over-reliance on email filters created a dangerous assumption that anything reaching the inbox was safe.

A weak user reporting culture meant employees who noticed something odd either dismissed it or lacked a clear, low-friction path to escalate the concern to security teams. Slow containment response compounded the damage. By the time incident response mobilized, attackers had already exfiltrated data, established persistence, and in cases like Merseyrail, weaponized the organization's own communication channels against it.

Every high-profile email malware incident reinforces the same truth. Organizations that train employees to recognize and report suspicious emails, run realistic phishing simulations across multiple channels, and maintain rapid triage workflows detect and contain email-borne threats before they become case studies. Building that detection capability starts with understanding how attackers structure their campaigns and where legacy defenses consistently break down.

How Malware Delivery Techniques Have Adapted to Modern Email Defenses

When Microsoft disabled macros by default on internet-sourced Office files in 2022, the result was a rapid, wholesale pivot in attacker techniques rather than a safer email ecosystem. Macro-enabled malware delivery collapsed by 66% within eight months and all but vanished from the threat landscape by early 2023.

The vacuum was filled within weeks as attackers flooded the gap with HTML smuggling, password-protected archives, AI-generated lures, and QR code-based payloads, techniques engineered specifically to sidestep the defenses organizations had just hardened.

The Decline of Macro-Based Attacks After Microsoft's MotW Restrictions

For over a decade, the malicious Office macro was the undisputed workhorse of email-borne malware delivery. A single .docm or .xlsm attachment with an embedded VBA script could initiate the entire infection chain: download a loader, establish persistence, deploy ransomware. All through functionality Microsoft built into its productivity suite.

That era ended abruptly. In 2022, Microsoft applied the Mark of the Web (MotW) designation to all Office files downloaded from the internet and blocked macro execution by default. The impact was immediate. By early 2023, macros had barely registered in cyberattack data. What had once powered roughly half of all email malware delivery collapsed to near-zero inside a year.

The real lesson is not that defenders secured a permanent win. It is that attackers, when dislodged from a primary vector, do not retreat. They retool. Within weeks of MotW enforcement, threat actors had already field-tested multiple replacement techniques and launched campaigns at scale.

Dark Reading documented how the speed and scope of these changes forced security teams into a reactive posture, rushing to write detection rules for techniques that were already being abandoned for the next variant.

The Rise of HTML Smuggling and Archive-Based Delivery

The most immediate successors to malicious macros were HTML smuggling and container-based delivery. HTML smuggling encodes a malicious payload, typically embedded inside an HTML attachment using JavaScript. When the recipient opens the file in a browser, the script reassembles the payload locally on the endpoint, bypassing email gateway inspection entirely because no recognizable malicious file crosses the network boundary.

Archive files, particularly password-protected ZIP and RAR formats, surged as the dominant malware delivery vehicle for the same reason: email security gateways could not unpack or scan them. Attackers presented these archives inside fake Adobe document viewers or SharePoint notifications, prompting victims to enter a supplied password. That small social engineering nudge bypassed an entire generation of perimeter defenses.

ISO files, LNK shortcuts, and OneNote notebooks each saw brief surges as attackers cycled through any file format capable of initiating code execution without triggering MotW restrictions. Multiple malware families, including QakBot and IcedID, pivoted to OneNote within months of its emergence as a vector.

None of these replacements have matched the durability macros once offered, but the experimentation velocity signals a permanently accelerated arms race. Attackers now cycle through techniques faster than most security teams update detection rules.

AI-Generated Content and Emerging Evasion Techniques

Two parallel developments are reshaping email malware delivery further. First, generative AI has erased the grammar errors, awkward phrasing, and localization flaws that security awareness training taught employees to recognize as phishing indicators. Attackers now produce fluent, contextually accurate business emails in any language, tailored to a target's industry, role, and internal communication patterns. The old heuristic of "look for typos" no longer works when AI writes cleaner prose than most humans.

Second, QR codes embedded in email bodies sidestep URL scanners entirely. Attackers present them as multi-factor authentication prompts, shared document links, or delivery notifications. The attack shifts the point of compromise from the desktop, where endpoint controls and browser protections exist, to mobile devices where security visibility is often minimal.

Kaspersky reported that QR code phishing detections surged fivefold between August and November 2025 alone, confirming this vector has rapidly scaled beyond experimental campaigns.

For a monthly subscription, operators without coding expertise can access HTML smuggling kits, AI-generated lure templates, and automated infrastructure that rotates domains and obfuscation techniques faster than threat intelligence feeds can update. The barrier to launching a multi-stage, evasive email malware campaign has dropped from requiring a skilled operator to requiring a credit card.

Phishing simulations that replicate these exact techniques, rather than last year's threats, are now the baseline for any security program that intends to keep pace.

How Security Awareness Training Prevents Email Malware Infections

Security awareness training prevents email malware infections because no technical filter catches every threat, and the employee receiving the email is the final detection opportunity.

Training transforms employees from passive targets into active defenders who can recognize and report the threats that slip past technical controls, creating a human detection layer between the inbox and a compromise.

The Human Layer as the Last Line of Defense

Email filters, sandboxing, and endpoint detection collectively block millions of threats. But attackers continuously test payloads against the most widely deployed security products before launching campaigns, refining their techniques until something gets through. AI-generated phishing emails now evade signature-based and behavioral detection engines with increasing precision.

When a malicious attachment or link lands in an employee's inbox, that employee is the final security control standing between the threat and the network.

The mechanism is straightforward: trained employees pause before clicking, scrutinize unexpected attachments, verify sender identities through a second channel, and report suspicious messages to security teams. Each of these micro-decisions interrupts the malware delivery chain at its most vulnerable point, the moment before a human being decides whether to trust what they are seeing. No firewall can make that decision for them.

What Effective Training Looks Like

Organizations that treat security awareness as an annual compliance checkbox see little behavioral change. An employee clicks through a 45-minute module in December, retains almost nothing by February, and faces the same phishing threats with the same untrained instincts. The training exists on paper but contributes nothing to actual defense.

Effective training operates on a fundamentally different model: it is continuous rather than periodic. Employees encounter short, focused microlearning modules, typically under 10 minutes, triggered by real-world behavior such as failing a simulated phishing test.

These simulations must mirror actual attack techniques: credential-harvesting landing pages, business email compromise (BEC) scenarios, malicious Office document attachments disguised as invoices, and increasingly, multi-channel attacks that combine email with voice or SMS follow-ups to build false credibility.

Organizations that deploy structured, simulation-based security awareness training see markedly different outcomes, because employees practice on threats that resemble what they will actually face rather than abstract scenarios from a compliance slide deck.

The goal is not to trick employees into embarrassment. It is to build genuine detection skills through repeated, low-stakes practice. When someone encounters a real malware-laden email after practicing on a dozen realistic simulations, the recognition is nearly automatic. Pattern recognition replaces anxious guesswork, and the organization gains a detection capability that scales across every inbox.

Measuring Behavioral Change Beyond Completion Rates

Completion percentages reveal only whether employees opened a module. They reveal nothing about whether anyone is actually safer. A 95% training completion rate paired with a 30% phishing simulation click-through rate exposes the gap between compliance theater and genuine risk reduction, a gap that attackers exploit daily.

Modern security programs track what employees do, beyond just what they finish. Phishing simulation click rates, reported-phish rates, and time-to-report are the metrics that measure whether training translates into safer decisions.

When an organization sees its simulation failure rate drop from 25% to under 5% over 12 months of consistent training, the return on investment becomes quantifiable. A 2025 meta-analysis published in Computers & Security by researchers at Leiden University found that security training produces a significant positive effect on end-user behavior (d = 0.75), with particularly strong results when programs assess behavioral predictors rather than knowledge recall alone.

Human risk scoring takes this further by aggregating simulation performance, training engagement, and real-world reporting behavior into a single metric per employee, team, and department. Security leaders can identify high-risk groups, target remediation where it matters most, and demonstrate to the board that the human layer is measurably stronger than it was last quarter.

Completion logs never told that story. Behavioral data does, and it is the only foundation worth building a training program on.

The Future of Email-Based Malware Delivery

Email-based malware delivery is being reshaped by three converging forces: generative AI, an expanding set of delivery channels, and the industrialization of cybercrime through service-based business models.

Security teams facing polymorphic malware, QR code-based attacks, and rentable ransomware kits are confronting a threat landscape where the attacker's cost and operational barrier have plummeted while the defender's burden has risen sharply.

AI-Powered Malware Campaigns

Generative AI has transformed email malware from a blunt instrument into a precision tool. Attackers use large language models to craft context-aware spear phishing emails that reference a target's actual job title, recent company announcements, and communication style. All of this is harvested from open-source intelligence (OSINT) and stitched together in seconds. These messages no longer carry the grammatical errors and generic greetings that once made phishing easy to identify.

Polymorphic malware takes this adaptability further. AI-driven variants now mutate their code signatures with each delivery, rendering traditional antivirus and signature-based detection ineffective. A Recorded Future analysis of H1 2025 malware trends documented ransomware groups adopting just-in-time hooking and memory injection techniques specifically designed to evade endpoint detection.

The threat does not stop at the inbox. Deepfake-augmented social engineering extends email attacks into voice and video channels. An employee receives a convincing vendor invoice via email, then gets a follow-up call from a cloned voice of the CFO confirming urgency.

This multi-channel coordination creates a psychological lock-in that single-channel defenses cannot break. Phishing simulation programs must replicate these convergent attack paths across email, voice, and video. Anything less prepares employees for threats that no longer exist in isolation.

QR Codes, Calendar Invites, and New Attack Vectors

Attackers are aggressively expanding beyond the email body itself. QR code phishing (quishing) has surged. Cybersecurity Dive reported threats using QR codes jumped from 7.6 million in January to 18.7 million by March 2026, a 146% increase that made it the fastest-growing email attack vector of the quarter.

QR codes bypass text-based email scanners entirely, routing victims to credential-harvesting sites on unmanaged mobile devices where corporate endpoint controls do not reach.

Calendar invite abuse has emerged as a parallel threat. Malicious .ics files arrive as meeting invitations that appear in familiar calendar interfaces, carrying embedded links or attachments that bypass the skepticism users typically apply to unsolicited email bodies.

Collaboration platform notifications, Teams messages, Slack DMs, and shared document alerts function as email-adjacent delivery channels that exploit the same trust reflexes while sidestepping email security gateways. The attack surface is no longer the inbox alone. It is every notification surface where an employee clicks without hesitation.

Malware-as-a-Service and the Democratization of Attacks

The industrialization of malware through malware-as-a-service (MaaS) and ransomware-as-a-service (RaaS) platforms has fundamentally reset the economics of cybercrime. Recorded Future's H1 2025 analysis documented ransomware groups like DragonForce rebranding as "cartels," offering flexible affiliate models that let independent operators use established ransomware infrastructure under their own branding. Anubis debuted an affiliate program letting partners monetize stolen data even when they lack the skills to deploy ransomware themselves.

The result is a volume-and-variety problem for defenders. When a technically unsophisticated actor can license a polished phishing kit, rent a ransomware payload, and launch a campaign against hundreds of organizations in an afternoon, the number of attacks any single organization faces multiplies.

The FBI's 2025 Internet Crime Complaint Center report recorded over one million complaints and nearly $21 billion in losses, a 26% increase from the prior year. Organizations that still treat email malware as a static, signature-detectable problem are calibrating their defenses for a threat landscape that expired two years ago.

Frequently Asked Questions About Email-Delivered Malware

Can Malware Be Contracted Just by Opening an Email, or Is User Interaction Required?

In nearly all modern email environments, simply opening and reading an email will not infect a device with malware. Infection almost always requires a user action: clicking a link, downloading and opening an attachment, enabling macros in a document, or entering credentials into a fake login page.

Modern email clients and webmail services block scripts from executing automatically when an email is opened, closing the vulnerability that made preview-pane infections possible in older platforms. The risk is not zero: exploits targeting unpatched email client vulnerabilities have occasionally enabled drive-by infections, but these are rare and rapidly patched.

The practical rule is that malware requires user interaction. This is why security awareness training that teaches employees to pause before clicking remains the most effective layer of defense after gateway filtering.

What are the warning signs that a device has been infected by email-delivered malware?

The most common warning signs include sudden system slowdowns, frequent crashes or freezes, unexpected pop-up advertisements, and browsers redirecting to unfamiliar websites. Additional signs include new toolbars, extensions, or applications that were not installed by the user, a spike in network activity when no programs are running, or antivirus software being disabled without the user's action.

The Federal Trade Commission identifies unexplained email messages sent from an account, files that suddenly become encrypted or inaccessible, and unauthorized password changes as critical indicators of compromise. In organizational settings, warning signs include unauthorized email forwarding rules appearing in inbox settings, unrecognized active sessions on an account, and colleagues reporting suspicious messages from a colleague's address. Any combination of these symptoms warrants immediate disconnection from the network and escalation to the security team.

How do password-protected archives evade detection by email security services?

Password-protected archives such as .zip, .rar, and .7z files evade detection because encryption prevents automated scanning engines from inspecting their contents. Traditional secure email gateways rely on signature-based detection and behavioral analysis, both of which require access to a file's contents to function.

When a file is encrypted, the scanner sees only scrambled data and cannot determine whether it contains malware. Attackers typically include the password in the email body itself or in a follow-up message, making it easy for the recipient to extract the payload.

According to Menlo Security, this technique has surged in popularity specifically because it defeats the most commonly deployed network and endpoint defenses. Some advanced platforms now attempt to extract passwords from surrounding text and decrypt archives for inspection, but this approach remains inconsistent across vendors.

How has AI changed the way attackers deliver malware through email?

AI has transformed email-based malware delivery in three critical ways. First, generative AI eliminates the spelling and grammar errors that once served as reliable red flags.

Second, AI enables attackers to personalize emails at scale by scraping publicly available information and crafting contextually relevant lures that reference real colleagues, projects, and events. Third, unregulated AI tools designed explicitly for cybercrime, such as WormGPT and FraudGPT, now generate polymorphic malware that mutates its code signature with each deployment, defeating signature-based detection.

The combination of flawless language, personalized pretexts, and mutating payloads means that traditional user training focused on spotting grammar mistakes is no longer sufficient for today's threat landscape.

See How Adaptive Security Reduces Email-Delivered Malware Risk

Email remains a dominant vector for malware delivery. When employees are trained to recognize the tactics attackers use, from password-protected archives to AI-generated lures, the organization's last line of defense becomes its strongest.

Take a self-guided tour of the Adaptive Security platform to see how role-based training and phishing simulations reduce malware risk across the workforce.

Adaptive Team

Adaptive Team

As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.

Get started with Adaptive Security

Get started

Human security for the AI era.