Malspam campaigns used Java Network Launch Protocol attachments (.jnlp) to bypass some email defenses and launch malware from victim systems with Java installed. In one case, a file posing as "Microsoft Secure Document Reader" directed Java to download delivery.jar from secured-doc-read[.]net, which then retrieved a second-stage payload from sec-doc-v[.]com/images/dsc0386234.jpg, saved it as C:\ProgramData\videodrv.exe, and attempted execution. Analysts noted that .jnlp files are plain XML rather than embedded executables, a trait that can help them slip past mail filters despite ultimately triggering code download and execution.
A separate campaign impersonated DHL with an invoice.jnlp attachment that downloaded a Java archive from invoicesecure[.]net, showed a fake error message as a decoy, and dropped C:\ProgramData\drvr32.exe, identified as Buer Loader. VIPRE reported the malware established persistence through the Startup folder, performed anti-analysis checks, gathered host details, and communicated with verstudiosan[.]com over HTTP GET and POST. The phishing operation also used forged headers, SPF softfail, and brand impersonation to increase credibility, underscoring that .jnlp attachments remain a viable delivery mechanism for staged malware infections.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
VIPRE noted that the Buer Loader malware family had first been observed in 2019 and is commonly distributed through malicious spam campaigns.
VIPRE analyzed a phishing campaign impersonating DHL that used forged email headers, DHL branding, and a .jnlp attachment named invoice.jnlp. The attachment downloaded a JAR from invoicesecure[.]net, showed a fake error, then fetched and executed drvr32.exe, which was identified as Buer Loader.
SANS analyzed an email-borne attack that used a malicious .jnlp attachment masquerading as a Microsoft secure document reader to download and run a JAR, which then fetched a PE payload. The technique relied on JNLP files being plain XML text files that may evade some mail filters while still launching Java code on systems with Java installed.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.