TecnoArtesanos Tech BlogTecnoArtesanos Tech Blog

Blog

0
Sergio Morales
Tuesday, 26 August 2025 / Published in Uncategorized

Warning for Windows Users: Global UpCrypter Phishing Attack is Expanding

A computer screen with program code warning of a detected malware script program.
Image: James Thew/Adobe Stock

Contents
  • UpCrypter’s role in the attack chain
    • Must-read security coverage
  • Global spread and affected sectors

Cybersecurity researchers have identified a surge of phishing emails targeting Microsoft Windows devices. Fortinet’s FortiGuard Labs tracks activity related to UpCrypter, a loader designed to install multiple types of remote access tools (RATs) that enable attackers to maintain prolonged access to compromised machines.

The phishing emails arrive disguised as missed voicemails or purchase orders. Victims who click on the attachments are redirected to fake websites, designed to appear convincing, often featuring company logos to increase trust.

According to Fortinet, these phishing pages prompt users to download a ZIP file containing a heavily disguised JavaScript dropper. Once opened, the script triggers PowerShell commands in the background that connect to attacker-controlled servers for the next stage of malware.

“These pages are designed to entice recipients into downloading JavaScript files that act as droppers for UpCrypter,” said Cara Lin, a Fortinet FortiGuard Labs researcher.

UpCrypter’s role in the attack chain

Once executed, UpCrypter scans the system to see if it is being analyzed in a sandbox or by forensic tools. If such monitoring is detected, the loader forces a reboot to break the investigation.

If no obstacles are found, the malware proceeds to download and run further payloads. In some cases, attackers conceal these files inside images through steganography, a tactic that helps bypass antivirus software detection.

The final malware deployed includes:

  • PureHVNC, which allows hidden remote desktop access.
  • DCRat (DarkCrystal RAT), a multifunction tool for spying and data theft.
  • Babylon RAT, which enables attackers to control a device fully.

Fortinet researchers noted that the attackers employ multiple methods to disguise malicious code, including string obfuscation, altering registry settings for persistence, and running code in-memory to prevent leaving traces on the disk.

Must-read security coverage

Global spread and affected sectors

The phishing campaign has been active since early August 2025 and has shown international reach, with high activity observed in Austria, Belarus, Canada, Egypt, India, and Pakistan.

The sectors hit hardest so far include manufacturing, technology, healthcare, construction, and retail/hospitality. Fortinet researchers also observed that detections doubled in just two weeks, demonstrating the rapid expansion of the operation.

This attack goes beyond stealing usernames and passwords; instead, it delivers a chain of malware designed to remain hidden within corporate systems for extended periods.

As Fortinet concluded, “Users and organizations should take this threat seriously, use strong email filters, and make sure staff are trained to recognize and avoid these types of attacks.”

Learn more from our detailed breakdown of Check Point’s report on escalating cyberattacks and how to stay protected in this shifting security climate.

What you can read next

Google’s Sec-Gemini v1 Takes on Hackers & Outperforms Rivals by 11%
Top Cloud Storage Providers in 2025
Nadie quiere informar cuánta energía usa la IA

Recent Posts

  • Los agentes de IA rebeldes no son malvados, solo quieren complacernos
  • Dime cómo prompteas y la IA te dirá quién eres
  • La primicia ahora la tienen los periodistas de IA. Spoiler: son malos reporteros
  • El reto de las empresas mexicanas ya no es la adopción de IA, sino aprender a aprovecharla
  • Bienvenidos a la era de la computación hecha con cerebros de verdad

Recent Comments

  1. A WordPress Commenter on Welcome to My Tech Blog – A New Chapter in Innovation

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • August 2016

Categories

  • Uncategorized

Recent Posts

  • Los agentes de IA rebeldes no son malvados, solo quieren complacernos

    Que los agentes de IA vayan libres hackeando ot...
  • Dime cómo prompteas y la IA te dirá quién eres

    A finales de 2022, cuando OpenAI lanzó ChatGPT,...
  • La primicia ahora la tienen los periodistas de IA. Spoiler: son malos reporteros

    En la conferencia de seguridad Black Hat celebr...
  • El reto de las empresas mexicanas ya no es la adopción de IA, sino aprender a aprovecharla

    La adopción de la inteligencia artificial (IA) ...
  • Bienvenidos a la era de la computación hecha con cerebros de verdad

    Te voy a contar un secreto. Cada célula de tu c...

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • August 2016

Categories

  • Uncategorized

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Kallyas

The #1 Multi-Purpose theme with a Powerful Visual Page Builder that you’ll actually enjoy.

Newsletter

 

sociall

 

Company

Customer

The #1 WordPress theme with a Powerful Visual Page Builder that you'll actually enjoy.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum.

Feed with such ID does not exist

Made with  ♥  by Hogash Studios. All Rights Reserved © 2016.

TOP