UpCrypter is a Windows malware loader/crypter used in multi-stage phishing and script-based infection chains to deliver remote access trojans. Reported delivery vectors include phishing emails with voicemail and purchase-order lures, HTML attachments that redirect victims to spoofed, personalized phishing pages, ZIP archives containing heavily obfuscated JavaScript droppers, and a Google Drive-hosted archive named UpCrypter.rar. In another analyzed chain, an obfuscated HTA progressed through VBScript, PowerShell, and .NET DLL stages, abused the LOLBIN DeviceCredentialDeployment.exe, downloaded systemprog.vbs via URLmon.dll/URLDownloadToFile, used FTP-hosted payload retrieval with embedded credentials, attempted persistence via the Windows Startup folder, and launched addinprocess32.exe to load malicious .NET DLLs such as ClassLibrary1 and ClassLibrary3.dll.
The malware’s observed behavior includes hidden PowerShell execution with ExecutionPolicy bypass, connectivity checks, extensive anti-analysis and anti-sandbox/anti-VM checks, in-memory loading of MSIL/.NET assemblies via reflection, staged downloads from remote infrastructure, writing content under APPDATA/LocalLow paths, execution via Interaction.Shell and WinExec, and persistence via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key. Analysis of a final .NET DLL protected with .NET Reactor indicated likely process-injection-related behavior, memory protection changes, remote string/payload download capability, file writes to APPDATA, and possible XOR/BitConverter-based decoding. FortiGuard reported that UpCrypter ultimately deployed multiple RAT payloads including PureHVNC, DCRat, and Babylon RAT.
Associated infrastructure and indicators directly mentioned in reporting include hxxps://drive[.]google[.]com/uc?export=download&id=1MsC6AGt5IrC9jbpx8RHCwHRIMIPWusv hosting UpCrypter.rar; phishing/redirect infrastructure such as hxxps://www[.]tridevresins[.]com/_b#, hxxps://maltashopping24[.]com/t#, and hxxps://brokaflex[.]com/tw/w.php; staging infrastructure including andrefelipedonascime1753562407700.0461178[.]meusitehostgator[.]com.br and ktc2005[.]com/bu[.]txt; and paste[.]ee URLs used in related retrieval chains. Fortinet attributed the tool to a developer handle, “Pjoao1578,” who allegedly demonstrated and updated it publicly on YouTube. A separate analysis noted a possible but unconfirmed link between an UpCrypter artifact and Blind Eagle (APT-C-36). Reported targeting was global and affected sectors included manufacturing, technology, healthcare, construction, and retail/hospitality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Among the information taken from the FTP server was a Google Drive URL, navigating here initiates a download of a .rar file called ‘UpCrypter.rar’.
1 distinct technique documented for this family, organized by ATT&CK tactic.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware loader delivered via phishing (fake voicemail/purchase order lures) to fetch/execute next-stage RAT payloads.
A multi-stage loader framework delivered via phishing that uses an obfuscated JavaScript dropper to launch PowerShell, perform connectivity and anti-analysis checks, download and in-memory execute an MSIL loader/DLL via .NET reflection, establish persistence via HKCU Run, and ultimately retrieve and deploy final-stage RAT payloads.
A password-protected RAR-hosted payload/crypter artifact retrieved during the infection-chain analysis; the content suggests it may be related to a malware delivery or packing component and notes possible relation to Blind Eagle/APT-C-36.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.