A phishing campaign targeting manufacturing companies across Europe, Asia and the Middle East has been running since April 2026, according to new research from cybersecurity firm Kaspersky. The operation has hit organisations in Malaysia, Egypt, the Czech Republic and Russia, with attackers posing as prospective buyers to harvest corporate credentials.
How the attack unfolds
The scheme runs in stages. Attackers first email employees posing as interested customers, asking for product pricing or availability. Once a target responds, they receive a link to what looks like technical specifications hosted on a legitimate cloud-based PDF service. The link instead leads to a fraudulent login page designed to steal corporate email credentials under the guise of a security check.
“Attackers are increasingly moving from simple schemes to complex campaigns consisting of multiple stages, as this increases the chances of a successful attack,” said Roman Dedenok, Anti-Spam Expert at Kaspersky.
Dedenok noted that attackers are tailoring their cover stories to the operating conditions of manufacturing firms specifically, and increasingly using AI tools to draft convincing phishing emails.
Regional exposure
Malaysia’s inclusion places the campaign squarely within Southeast Asia’s manufacturing base, a sector regional cybersecurity teams have flagged as under-resourced relative to the sophistication of incoming threats.
Recommended defences
- Deploy mail server security tools that counter phishing, business email compromise and QR code-based attacks
- Maintain up-to-date threat intelligence feeds on attacker tactics and procedures
- Run structured cyber literacy training for staff, particularly those in customer-facing sales roles
Kaspersky said the campaign remains active and organisations in the affected sectors should treat unsolicited buyer inquiries requesting document downloads with heightened scrutiny.

