Hackers Use UpCrypter and Phishing Tricks to Take Over Devices
Cybersecurity experts have discovered a phishing campaign that uses fake voicemail and purchase order emails to spread malicious software called UpCrypter. The emails link to fake websites that look real by using company logos and domains. Victims are tricked into downloading a ZIP file with a hidden script that installs remote access tools, giving hackers full control of the device. The campaign started in August 2025 and mainly targets industries like manufacturing, healthcare, tech, and retail, especially in countries like Austria, India, and Canada. Hackers use smart tricks to avoid detection, such as hiding malicious software in images and avoiding file traces. In a related attack, scammers abused Google Classroom to send over 115,000 phishing emails, redirecting victims to WhatsApp scams. These attacks are part of a growing trend called “living off trusted sites” (LOTS), where hackers abuse trusted platforms like Microsoft 365 and Zoom to bypass security. In response, companies are rolling out new protections.
To stay safe, follow these tips:
- Be cautious of unexpected emails, especially those with links or attachments.
- Verify the sender’s identity before clicking on links or downloading files.
- Avoid downloading ZIP or JavaScript files from unfamiliar sources.
- Keep your software and antivirus programs updated.
- Use multi-factor authentication (MFA) on all important accounts.
- Report suspicious emails to your IT or security team immediately.
- Don’t trust emails that appear to come from known platforms without verifying their purpose.
Source: https://thehackernews.com/2025/08/phishing-campaign-uses-upcrypter-in.html