BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Fake Voicemails Spread UpCrypter Malware in Global Phishing Surge

Sophisticated UpCrypter Phishing Campaign Exploits Trusted Platforms to Target Global Industries

  • New phishing campaign uses fake voicemails and purchase orders to distribute UpCrypter Malware loader.
  • The attacks target sectors like manufacturing, technology, healthcare, construction, and retail worldwide, focusing on countries such as Austria, Belarus, Canada, Egypt, India, and Pakistan.
  • UpCrypter delivers remote access tools, enabling attackers to control infected devices and evade detection.
  • Threat actors abuse trusted services like Google Classroom, Discord, and Microsoft 365 to improve the success of phishing attacks.
  • Attackers use advanced anti-detection techniques, including script-based evasion and steganography, to hide malicious activity and avoid analysis.

A phishing campaign is spreading malware known as UpCrypter through fake voicemail and purchase order emails, according to Cybersecurity researchers. The campaign began targeting major industries in several countries in August 2025. One of its main goals is to deploy a malware loader, which installs remote access tools (RATs) on compromised systems.

- Advertisement -

Researchers at Fortinet FortiGuard Labs found that the attackers use convincing emails that direct recipients to phishing pages. These sites ask users to download JavaScript files, which act as delivery vehicles for UpCrypter. Most attacks have targeted manufacturing, technology, healthcare, construction, and retail, with infection reports mainly in Austria, Belarus, Canada, Egypt, India, and Pakistan.

According to Fortinet, UpCrypter helps attackers install a range of RATs, such as PureHVNC RAT, DCRat (also known as DarkCrystal RAT), and Babylon RAT. These allow attackers to gain full control over infected computers. The infection usually begins with a phishing message about a voicemail or a purchase, encouraging the target to visit a fraudulent site and download a ZIP archive. This file contains an obfuscated JavaScript loader, which checks for Sandbox or forensic tools before allowing the next steps.

The loader downloads the final malicious payload—sometimes hidden inside harmless images using a method called steganography—which helps avoid detection. The malware can also be distributed as an MSIL loader, which performs similar anti-analysis checks before downloading a script, dynamic link library (DLL), and the main payload. These files combine during execution, running in memory without writing them to the disk, making it difficult to track.

Similar attacks have been seen abusing Google Classroom to send over 115,000 phishing emails to 13,500 organizations in early August 2025, as reported by Check Point. Attackers used trusted technology platforms to bypass email security protocols like SPF, DKIM, and DMARC, increasing the chance that harmful messages reach users’ inboxes. Some campaigns sent fake invitations containing offers or instructions for contacting scammers, frequently via WhatsApp.

- Advertisement -

Threat actors also misuse services such as Microsoft 365 Direct Send, Discord CDN, SendGrid, and others to achieve these goals. New defense measures, like Microsoft’s “Reject Direct Send” and custom policies, aim to counter these attacks. Attackers have adapted by using client-side scripts to block automated and manual analysis and sometimes host phishing pages within virtual desktops or embed anti-analysis scripts into phishing kits.

These evolving techniques indicate an ongoing effort by threat actors to create sophisticated and hard-to-detect phishing threats. Links to further details and technical research can be found in the statements by Fortinet (here) and Check Point (here).

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Senate CLARITY Act adds Dem customer protections

The US Senate is nearing a vote on the Digital Asset Market Clarity (CLARITY)...

FakeGit campaign uses 800 fake AI tools to spread SmartLoader malware

Cybersecurity researchers uncovered nearly 7,600 malicious GitHub repositories in the FakeGit campaign, with over...

Google’s New Frozen v2 Chip Aims for 2028 Launch

Google is developing a new server chip called Frozen v2, designed to optimize its...

Russia Duma approves crypto for international trade

Russia's State Duma will hold final votes on a comprehensive crypto bill on July...

Saylor breaks 2.5x mNAV promise, stock plummets 75%

Strategy sold $14.3 billion of MSTR stock below the 2.5x mNAV threshold it pledged...

Must Read

9 Best Books On Ethereum And Blockchain Technology

QUICK LINKSHow to Choose Your First Blockchain Book: A Simple Framework1. Define Your Goal: Are you looking to Build, Invest, or Understand?2. Assess Your...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading