Target Industry

Manufacturing, technology, healthcare, construction, and retail sectors globally. 

Overview

Cyber security researchers have identified a malicious phishing campaign using fake voicemail and purchase order emails to distribute a malware loader named UpCrypter. These emails link to convincing phishing pages that prompt users to download JavaScript files acting as droppers for the malware. 

Impact

Recent phishing and malware campaigns pose serious risks to organisations. Threat actors can gain access to internal systems through stolen credentials, while remote access trojans (RATs) like PureHVNC enable remote control and data theft. These threats often evade detection due to in-memory execution and anti-analysis techniques. Reputational damage is also a concern, as abuse of trusted platforms undermines user confidence, and compromised customer data may lead to legal consequences. Financially, organisations face costs from incident response, regulatory fines, and operational disruption. 

Exploitation

Phishing emails are designed to mimic voicemail alerts or purchase notifications, directing victims to landing pages that display their organisation’s domain and logo to appear legitimate. The payload is usually a ZIP file containing obfuscated JavaScript, which checks for forensic tools before downloading further malware. Steganography is used to hide malicious code within images, and in some cases, the malware is delivered via a Microsoft Intermediate Language (MSIL) loader with anti-analysis features. MSIL is a low-level language used by .NET applications, enabling cross-platform code execution within the .NET framework. 

Containment, Mitigations & Remediations

To mitigate the UpCrypter phishing campaign, organisations should block suspicious ZIP and JavaScript attachments, enforce email authentication protocols, and use sandboxing for email links. Users should be trained to spot and report fake voicemail or purchase emails. Endpoint protection tools should detect obfuscated scripts and RATs, while network segmentation and cloud monitoring help limit spread. Threat hunting should focus on steganographic payloads and fake browser templates, and infrastructure should be hardened against abuse of trusted platforms and AI site builders. 

Threat Landscape

The cyber threat landscape is increasingly complex, with threat actors using advanced phishing tactics and obfuscated malware like UpCrypter to bypass defences. Threat actors are now abusing trusted platforms such as Microsoft 365 Direct Send, OneNote, Discord CDN, and Zoom to host or deliver malicious content. RATs, steganography and AI-generated lures are becoming more common, targeting both individuals and organisations. Effective mitigation requires proactive defence, user education and strong threat intelligence. 

Threat Group

No specific threat group has been publicly linked to the UpCrypter phishing campaign. However, the use of multiple RATs and shared infrastructure suggests it may be part of a broader Phishing-as-a-Service operation. 

Further Information

Fortinet bulletin 

Intelligence Terminology Yardstick

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content