Phishing Campaign Uses UpCrypter in Fake Voicemail Emails to Deliver RAT Payloads
Researchers studying cybersecurity have discovered a new phishing effort that distributes the malware loader UpCrypter by posing as purchase orders and voicemails.
According to Cara Lin, a researcher at Fortinet FortiGuard Labs, the effort uses expertly constructed emails to spread malicious URLs that lead to plausible phishing pages. The purpose of these pages is to persuade users to download JavaScript files that serve as UpCrypter droppers.
Since the beginning of August 2025, attacks that spread the malware have mostly targeted the manufacturing, technology, healthcare, construction, and retail/hospitality industries worldwide. Among other places, Austria, Belarus, Canada, Egypt, India, and Pakistan have reported the great bulk of the infections.
An attacker can gain complete ...

