{"id":1458,"date":"2025-08-26T19:55:08","date_gmt":"2025-08-26T19:55:08","guid":{"rendered":"https:\/\/www.techrepublic.com\/?p=4324044"},"modified":"2025-08-26T19:55:08","modified_gmt":"2025-08-26T19:55:08","slug":"warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding","status":"publish","type":"post","link":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/","title":{"rendered":"Warning for Windows Users: Global UpCrypter Phishing Attack is Expanding"},"content":{"rendered":"<figure class=\"featured-image aligncenter wp-caption\"> <picture class=\"image\"><img loading=\"lazy\" width=\"270\" height=\"203\" src=\"https:\/\/assets.techrepublic.com\/uploads\/2025\/08\/tr_20240605-cisco-talos-lilacsquid-purpleink-malware-770x495-2-270x203.jpg\" class=\"attachment-thumbnail size-thumbnail\" alt=\"A computer screen with program code warning of a detected malware script program.\" srcset=\"https:\/\/assets.techrepublic.com\/uploads\/2025\/08\/tr_20240605-cisco-talos-lilacsquid-purpleink-malware-770x495-2-540x347.jpg 540w, https:\/\/assets.techrepublic.com\/uploads\/2025\/08\/tr_20240605-cisco-talos-lilacsquid-purpleink-malware-770x495-2-270x174.jpg 270w\" sizes=\"auto, (max-width: 400px) 50vw, (max-width: 600px) 100vw, (max-width: 979px) 100vw, (max-width: 1369px) 50vw, 770px\" decoding=\"async\"><\/picture><figcaption>Image: James Thew\/Adobe Stock<\/figcaption><\/figure>\n<p> <meta property=\"image\" content=\"https:\/\/assets.techrepublic.com\/uploads\/2025\/08\/tr_20240605-cisco-talos-lilacsquid-purpleink-malware-770x495-2-540x347.jpg\"> <\/p>\n<p>Cybersecurity researchers have identified a surge of phishing emails targeting Microsoft Windows devices. Fortinet\u2019s FortiGuard Labs tracks activity related to UpCrypter, a loader designed to install multiple types of remote access tools (RATs) that enable attackers to maintain prolonged access to compromised machines.<\/p>\n<p>The phishing emails arrive disguised as missed voicemails or purchase orders. Victims who click on the attachments are redirected to fake websites, designed to appear convincing, often featuring company logos to increase trust.<\/p>\n<p>According to Fortinet, these phishing pages prompt users to download a ZIP file containing a heavily disguised JavaScript dropper. Once opened, the script triggers PowerShell commands in the background that connect to attacker-controlled servers for the next stage of malware.<\/p>\n<p>\u201cThese pages are designed to entice recipients into downloading JavaScript files that act as droppers for UpCrypter,\u201d <a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/phishing-campaign-targeting-companies-via-upcrypter\">said Cara Lin<\/a>, a Fortinet FortiGuard Labs researcher.<\/p>\n<p> <!-- ICP Plugin: Start --><!-- ICP Plugin: End --><\/p>\n<h2><span class=\"ez-toc-section\" id=\"UpCrypters_role_in_the_attack_chain\"><\/span>UpCrypter\u2019s role in the attack chain<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Once executed, UpCrypter scans the system to see if it is being analyzed in a sandbox or by forensic tools. If such monitoring is detected, the loader forces a reboot to break the investigation.<\/p>\n<p>If no obstacles are found, the malware proceeds to download and run further payloads. In some cases, attackers conceal these files inside images through steganography, a tactic that helps bypass <a href=\"https:\/\/www.techrepublic.com\/article\/best-antivirus-software\/\">antivirus software<\/a> detection.<\/p>\n<p>The final malware deployed includes:<\/p>\n<ul>\n<li><strong>PureHVNC,<\/strong> which allows hidden remote desktop access.<\/li>\n<li><strong>DCRat (DarkCrystal RAT),<\/strong> a multifunction tool for spying and data theft.<\/li>\n<li><strong>Babylon RAT,<\/strong> which enables attackers to control a device fully.<\/li>\n<\/ul>\n<p>Fortinet researchers noted that the attackers employ multiple methods to disguise malicious code, including string obfuscation, altering registry settings for persistence, and running code in-memory to prevent leaving traces on the disk.<\/p>\n<aside class=\"pinbox right\">\n<h3 class=\"heading\">Must-read security coverage<\/h3>\n<\/aside>\n<h2><span class=\"ez-toc-section\" id=\"Global_spread_and_affected_sectors\"><\/span>Global spread and affected sectors<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The <a href=\"https:\/\/www.techrepublic.com\/article\/darktrace-threat-report\/\">phishing campaign<\/a> has been active since early August 2025 and has shown international reach, with high activity observed in Austria, Belarus, Canada, Egypt, India, and Pakistan.<\/p>\n<p>The sectors hit hardest so far include manufacturing, technology, healthcare, construction, and retail\/hospitality. Fortinet researchers also observed that detections doubled in just two weeks, demonstrating the rapid expansion of the operation.<\/p>\n<p>This attack goes beyond stealing usernames and passwords; instead, it delivers a chain of malware designed to remain hidden within corporate systems for extended periods.<\/p>\n<p>As Fortinet concluded, \u201cUsers and organizations should take this threat seriously, use strong email filters, and make sure staff are trained to recognize and avoid these types of attacks.\u201d<\/p>\n<p>Learn more from our detailed breakdown of <a href=\"https:\/\/www.techrepublic.com\/article\/news-cyber-attacks-check-point\/\">Check Point\u2019s report on escalating cyberattacks<\/a> and how to stay protected in this shifting security climate.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Image: James Thew\/Adobe Stock Cybersecurity researchers have identified a surge of phishing emails targeting Microsoft Windows devices. Fortinet\u2019s FortiGuard Labs tracks activity related to UpCrypter, a loader designed to install multiple types of remote access tools (RATs) that enable attackers to maintain prolonged access to compromised machines. The phishing emails arrive disguised as missed voicemails [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1459,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1458","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Warning for Windows Users: Global UpCrypter Phishing Attack is Expanding - TecnoArtesanos Tech Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Warning for Windows Users: Global UpCrypter Phishing Attack is Expanding - TecnoArtesanos Tech Blog\" \/>\n<meta property=\"og:description\" content=\"Image: James Thew\/Adobe Stock Cybersecurity researchers have identified a surge of phishing emails targeting Microsoft Windows devices. Fortinet\u2019s FortiGuard Labs tracks activity related to UpCrypter, a loader designed to install multiple types of remote access tools (RATs) that enable attackers to maintain prolonged access to compromised machines. The phishing emails arrive disguised as missed voicemails [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/\" \/>\n<meta property=\"og:site_name\" content=\"TecnoArtesanos Tech Blog\" \/>\n<meta property=\"article:published_time\" content=\"2025-08-26T19:55:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/assets.techrepublic.com\/uploads\/2025\/08\/tr_20240605-cisco-talos-lilacsquid-purpleink-malware-770x495-2-270x203.jpg\" \/>\n<meta name=\"author\" content=\"Sergio Morales\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sergio Morales\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/\",\"url\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/\",\"name\":\"Warning for Windows Users: Global UpCrypter Phishing Attack is Expanding - TecnoArtesanos Tech Blog\",\"isPartOf\":{\"@id\":\"https:\/\/blog.tecnoartesanos.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/blog.tecnoartesanos.com\/wp-content\/uploads\/2025\/08\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding.jpg\",\"datePublished\":\"2025-08-26T19:55:08+00:00\",\"author\":{\"@id\":\"https:\/\/blog.tecnoartesanos.com\/#\/schema\/person\/ec88bc1410fd158963717c4216f04807\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/#primaryimage\",\"url\":\"https:\/\/blog.tecnoartesanos.com\/wp-content\/uploads\/2025\/08\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding.jpg\",\"contentUrl\":\"https:\/\/blog.tecnoartesanos.com\/wp-content\/uploads\/2025\/08\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding.jpg\",\"width\":270,\"height\":203},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.tecnoartesanos.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Warning for Windows Users: Global UpCrypter Phishing Attack is Expanding\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.tecnoartesanos.com\/#website\",\"url\":\"https:\/\/blog.tecnoartesanos.com\/\",\"name\":\"TecnoArtesanos Tech Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.tecnoartesanos.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.tecnoartesanos.com\/#\/schema\/person\/ec88bc1410fd158963717c4216f04807\",\"name\":\"Sergio Morales\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.tecnoartesanos.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/3d45178fc8fbbe32d39278bc504fa9093f947f406ff4f1ddcfa27505ab772184?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/3d45178fc8fbbe32d39278bc504fa9093f947f406ff4f1ddcfa27505ab772184?s=96&d=mm&r=g\",\"caption\":\"Sergio Morales\"},\"sameAs\":[\"https:\/\/sergiomorales.space\"],\"url\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/author\/sergiomorales\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Warning for Windows Users: Global UpCrypter Phishing Attack is Expanding - TecnoArtesanos Tech Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/","og_locale":"en_US","og_type":"article","og_title":"Warning for Windows Users: Global UpCrypter Phishing Attack is Expanding - TecnoArtesanos Tech Blog","og_description":"Image: James Thew\/Adobe Stock Cybersecurity researchers have identified a surge of phishing emails targeting Microsoft Windows devices. Fortinet\u2019s FortiGuard Labs tracks activity related to UpCrypter, a loader designed to install multiple types of remote access tools (RATs) that enable attackers to maintain prolonged access to compromised machines. The phishing emails arrive disguised as missed voicemails [&hellip;]","og_url":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/","og_site_name":"TecnoArtesanos Tech Blog","article_published_time":"2025-08-26T19:55:08+00:00","og_image":[{"url":"https:\/\/assets.techrepublic.com\/uploads\/2025\/08\/tr_20240605-cisco-talos-lilacsquid-purpleink-malware-770x495-2-270x203.jpg","type":"","width":"","height":""}],"author":"Sergio Morales","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sergio Morales","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/","url":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/","name":"Warning for Windows Users: Global UpCrypter Phishing Attack is Expanding - TecnoArtesanos Tech Blog","isPartOf":{"@id":"https:\/\/blog.tecnoartesanos.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/#primaryimage"},"image":{"@id":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.tecnoartesanos.com\/wp-content\/uploads\/2025\/08\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding.jpg","datePublished":"2025-08-26T19:55:08+00:00","author":{"@id":"https:\/\/blog.tecnoartesanos.com\/#\/schema\/person\/ec88bc1410fd158963717c4216f04807"},"breadcrumb":{"@id":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/#primaryimage","url":"https:\/\/blog.tecnoartesanos.com\/wp-content\/uploads\/2025\/08\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding.jpg","contentUrl":"https:\/\/blog.tecnoartesanos.com\/wp-content\/uploads\/2025\/08\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding.jpg","width":270,"height":203},{"@type":"BreadcrumbList","@id":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/08\/26\/warning-for-windows-users-global-upcrypter-phishing-attack-is-expanding\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.tecnoartesanos.com\/"},{"@type":"ListItem","position":2,"name":"Warning for Windows Users: Global UpCrypter Phishing Attack is Expanding"}]},{"@type":"WebSite","@id":"https:\/\/blog.tecnoartesanos.com\/#website","url":"https:\/\/blog.tecnoartesanos.com\/","name":"TecnoArtesanos Tech Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.tecnoartesanos.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.tecnoartesanos.com\/#\/schema\/person\/ec88bc1410fd158963717c4216f04807","name":"Sergio Morales","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.tecnoartesanos.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/3d45178fc8fbbe32d39278bc504fa9093f947f406ff4f1ddcfa27505ab772184?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/3d45178fc8fbbe32d39278bc504fa9093f947f406ff4f1ddcfa27505ab772184?s=96&d=mm&r=g","caption":"Sergio Morales"},"sameAs":["https:\/\/sergiomorales.space"],"url":"https:\/\/blog.tecnoartesanos.com\/index.php\/author\/sergiomorales\/"}]}},"_links":{"self":[{"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/posts\/1458","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/comments?post=1458"}],"version-history":[{"count":0,"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/posts\/1458\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/media\/1459"}],"wp:attachment":[{"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/media?parent=1458"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/categories?post=1458"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/tags?post=1458"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}