Cybercriminals have significantly increased the use of concealed JavaScript and steganography to deliver malware through business-themed email attacks in the third quarter of 2025. Security researchers at Forcepoint X-Labs observed a surge in malicious emails disguised as legitimate business communications, such as purchase orders, shipment notifications, and payment requests. These emails often contain compressed archive attachments (ZIP, RAR, 7z, or TAR) that include heavily obfuscated JavaScript files. The obfuscation is designed to evade detection by security tools, making it difficult for traditional email filters to identify the threat. Once a recipient opens the JavaScript file, it leverages legitimate Windows utilities like PowerShell and Windows Management Instrumentation (WMI) to execute commands, a technique known as 'Living off the Land' (LotL). This approach allows attackers to operate without raising immediate suspicion or triggering standard security alerts. A notable aspect of these campaigns is the use of steganography, where malicious code is hidden within seemingly innocuous image files. The JavaScript downloader decodes Base64-encoded DLL or EXE payloads embedded in these images, further complicating detection. Payloads identified in these attacks include well-known malware families such as Agent Tesla, Remcos RAT, DarkCloud, and FormBook, each capable of stealing sensitive information or providing remote access to compromised systems. The campaigns are highly targeted, with lures localized in multiple languages, including English and Spanish, to increase their effectiveness against non-English speaking businesses. Subject lines like “RE: Payment Swift MT103” and “DHL Shipment Notification” are commonly used to entice recipients into opening the attachments. The sophistication of these attacks, including the use of legitimate system tools and advanced concealment techniques, allows them to bypass many conventional security defenses. Security experts recommend organizations implement advanced email filtering, strengthen endpoint security, and conduct regular user awareness training to mitigate the risk. The trend highlights the evolving tactics of threat actors who continuously adapt to evade detection and maximize the impact of their campaigns. Organizations are urged to remain vigilant and update their security protocols to address these emerging threats. The use of steganography in malware delivery represents a significant challenge for defenders, as it requires more advanced analysis to uncover hidden payloads. The ongoing evolution of these attack methods underscores the importance of a multi-layered security approach. Businesses are advised to monitor for unusual activity related to PowerShell and WMI, as these are commonly abused in such attacks. The widespread nature of these campaigns suggests that organizations of all sizes and sectors are at risk. Collaboration between security vendors and enterprises is essential to develop effective countermeasures. The research underscores the need for continuous threat intelligence sharing to stay ahead of rapidly changing attack techniques. Ultimately, the rise in JavaScript and steganography-based malware delivery marks a new phase in email-borne threats, demanding heightened awareness and proactive defense strategies.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Campaigns observed in this period delivered malware families including Agent Tesla, Remcos RAT, DarkCloud, and FormBook through the concealed JavaScript and steganography techniques. Shipment-notification themed emails were among the social engineering lures used to infect targets.
By Q3 2025, attackers were using Windows Management Instrumentation and PowerShell to execute commands after victims opened the malicious JavaScript. They also hid malicious code inside image files using steganography to further evade detection.
During the third quarter of 2025, researchers observed a significant increase in malware delivered through JavaScript files concealed inside compressed archives. The lures commonly arrived via malicious emails masquerading as purchase orders, quotes, and shipment notifications.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.