logo

Phishing Campaign Targeting Companies via UpCrypter

ID: 59885c0f-793f-5173-b1bc-5e803a4d4461

STIX ID: report--59885c0f-793f-5173-b1bc-5e803a4d4461

Feed Name: Fortinet Blog

Threat Score
78/100

Date Published: 2025-08-25

Date Updated: 2026-04-27

...
...

Fortinet FortiGuard Labs identified a global phishing campaign that uses obfuscated HTML/JavaScript lures to redirect recipients to personalized phishing pages which deliver a ZIP containing an obfuscated JavaScript loader (UpCrypter). UpCrypter decodes and executes a .NET loader in memory, performs anti-analysis and anti-VM checks, establishes persistence via HKCU Run, and stages multiple remote access tools (PureHVNC, DCRat, Babylon RAT); the report includes network and file IOCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.