Target Industry
Manufacturing, technology, healthcare, construction, and retail sectors globally.
Overview
Cyber security researchers have identified a malicious phishing campaign using fake voicemail and purchase order emails to distribute a malware loader named UpCrypter. These emails link to convincing phishing pages that prompt users to download JavaScript files acting as droppers for the malware.
Impact
Recent phishing and malware campaigns pose serious risks to organisations. Threat actors can gain access to internal systems through stolen credentials, while remote access trojans (RATs) like PureHVNC enable remote control and data theft. These threats often evade detection due to in-memory execution and anti-analysis techniques. Reputational damage is also a concern, as abuse of trusted platforms undermines user confidence, and compromised customer data may lead to legal consequences. Financially, organisations face costs from incident response, regulatory fines, and operational disruption.
Exploitation
Phishing emails are designed to mimic voicemail alerts or purchase notifications, directing victims to landing pages that display their organisation’s domain and logo to appear legitimate. The payload is usually a ZIP file containing obfuscated JavaScript, which checks for forensic tools before downloading further malware. Steganography is used to hide malicious code within images, and in some cases, the malware is delivered via a Microsoft Intermediate Language (MSIL) loader with anti-analysis features. MSIL is a low-level language used by .NET applications, enabling cross-platform code execution within the .NET framework.
Containment, Mitigations & Remediations
To mitigate the UpCrypter phishing campaign, organisations should block suspicious ZIP and JavaScript attachments, enforce email authentication protocols, and use sandboxing for email links. Users should be trained to spot and report fake voicemail or purchase emails. Endpoint protection tools should detect obfuscated scripts and RATs, while network segmentation and cloud monitoring help limit spread. Threat hunting should focus on steganographic payloads and fake browser templates, and infrastructure should be hardened against abuse of trusted platforms and AI site builders.
Threat Landscape
The cyber threat landscape is increasingly complex, with threat actors using advanced phishing tactics and obfuscated malware like UpCrypter to bypass defences. Threat actors are now abusing trusted platforms such as Microsoft 365 Direct Send, OneNote, Discord CDN, and Zoom to host or deliver malicious content. RATs, steganography and AI-generated lures are becoming more common, targeting both individuals and organisations. Effective mitigation requires proactive defence, user education and strong threat intelligence.
Threat Group
No specific threat group has been publicly linked to the UpCrypter phishing campaign. However, the use of multiple RATs and shared infrastructure suggests it may be part of a broader Phishing-as-a-Service operation.
Further Information
Intelligence Terminology Yardstick













