Phishing Campaign Targeting Companies via UpCrypter

Aug. 26, 2025, 8:27 a.m.

Description

A sophisticated phishing campaign has been identified, utilizing carefully crafted emails to deliver malicious URLs linked to convincing phishing pages. These pages entice recipients to download JavaScript files that act as droppers for UpCrypter, a malware that ultimately deploys various remote access tools (RATs). The attack chain begins with obfuscated scripts redirecting victims to spoofed sites personalized with the target's email domain. The campaign uses different lures, including voicemail-themed and purchase order-themed emails. UpCrypter, the central loader framework, stages and deploys multiple RATs, including PureHVNC, DCRat, and Babylon RAT. The malware employs anti-VM and anti-analysis techniques, downloads additional payloads, and establishes persistence. This campaign operates globally, affecting multiple industries, and demonstrates an adaptable threat delivery ecosystem capable of bypassing defenses and maintaining persistence across different environments.

Date

  • Created: Aug. 26, 2025, 12:06 a.m.
  • Published: Aug. 26, 2025, 12:06 a.m.
  • Modified: Aug. 26, 2025, 8:27 a.m.

Indicators

  • f2633ef3030c28238727892d1f2fcb669d23a803e035a5c37fd8b07dce442f17
  • c7b6205c411a5c0fde873085f924f6270d49d103f57e7e7ceb3deb255f3e6598
  • c0bfa10d2739acd6ee11b8a2e2cc19263e18db0bbcab929a133eaaf1a31dc9a5
  • a5fe77344a239af14c87336c65e75e59b69a59f3420bd049da8e8fd0447af235
  • 7e832ab8f15d826324a429ba01e49b452ffc163ca4af8712a6b173f40c919b43
  • 4b03950d0ace9559841a80367f66c1cd84ce452d774d65c8ab628495d403ad0f
  • www.tridevresins.com
  • https://www.tridevresins.com/_b#.
  • https://maltashopping24.com/t
  • https://brokaflex.com/tw/w.xn--php-9o0a
  • https://andrefelipedonascime1753562407700.0461178.meusitehostgator.com.br/sPVbqMbKYr_06/03.txt.”
  • http://power-builders.net/vn/v.php
  • http://ktc2005.com/bu.txt
  • http://ktc2005.com/bu.txt.xn--ivg
  • http://manitouturkiye.com/cz/z.php
  • http://brokaflex.com/tw/w.php
  • xtadts.ddns.net
  • webdot.ddns.net
  • andrefelipedonascime1753562407700.0461178.meusitehostgator.com.br
  • power-builders.net
  • samsunbilgisayartamiri.com
  • afxwd.ddns.net
  • manitouturkiye.com
  • maltashopping24.com
  • ktc2005.com
  • hacvietsherwin.com
  • brokaflex.com
  • adanaaysuntemizlik.com
  • capitalestates.es

Attack Patterns

Additional Informations

  • Construction
  • Retail
  • Hospitality
  • Technology
  • Healthcare
  • Manufacturing