Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

UpCrypter

56
Global rank
62 infographic chevron month
Month rank
56 infographic chevron week
Week rank
0
IOCs

UpCrypter is a sophisticated malware loader that functions as a delivery mechanism for remote access tools. Distributed through global phishing campaigns targeting Windows systems, this actively maintained tool serves as the central framework for deploying various RATs including PureHVNC, DCRat, and Babylon RAT, enabling attackers to establish persistent remote control over compromised systems.

Loader
Type
Unknown
Origin
1 June, 2025
First seen
27 August, 2026
Last seen

How to analyze UpCrypter with ANY.RUN

Type
Unknown
Origin
1 June, 2025
First seen
27 August, 2026
Last seen

IOCs

IP addresses
74.178.240.51
52.123.129.14
2.23.246.9
48.192.1.64
150.171.28.11
23.55.110.196
16.15.237.67
52.111.224.7
48.209.6.48
192.178.183.113
150.171.22.17
48.209.138.168
150.171.109.105
57.153.246.3
204.79.197.203
48.209.138.189
40.126.31.131
2.16.168.50
172.211.123.248
150.171.109.101
Hashes
d1614ad99aded9f6f5c1be7fe7ffa5124bd04a526580da3818ea8a954e852aa6
0cf098dfe5bbb46fc0132b3cf0c54b06b4d2c8390d847ee2a65d20f9b7480f4c
9b32c491d0bfebdca1455f73c3c6f71796d433a39818c06c353da588de650f81
2824cf97513dc3ecc261f378bfd595ae95a5997e9d1c63f5731a58b1f8cd54f9
64e01bc292ba2ea1699576fcc445367047520ee895e290ccee20c24c9336d8ef
2445cad863be47bb1c15b57a4960b7b0d01864e63cdfde6395f3b2689dc1444b
ff702ca753a7e3b75f9d9850cc9343e28e8d60f8005a2c955c8ac2105532b2c9
af889c1deb6f9248961c2f8ba4307a8206d7163616a5b7455d17cead00068317
728d8cbd71263680a4e41399db65b3f2b8175d50ca630afd30643ced9ffe831f
22bc37b47ce8a832f39701641dc358357676e9be187a93a4c5d4b016e29238ae
cc3e9077fcc9bd0dfc5dd3924c6c48b8345f32cee24fccc508c279f45b2abe61
14895bf43ce9b76c0ff4f9aef93dbe8bb6ca496894870cf0c007b189e0cef00e
7ccc7b17bfe01c3c7dd33eff8f80d0b57fc9b175815e766c9c1c1e893725e20f
6c69ce0fe6fab14f1990a320d704fee362c175c00eb6c9224aa6f41108918ca6
5f4229d18e5606330146ee13bdf726e10c1e06cbb15368c47f1ae68abe9ce4ba
ec78ddd4ccf32b5d76ec701a20167c3fbd146d79a505e4fb0421fc1e5cf4aa63
41ce6a7b18364efecced0419b42165d4f86c43643bbe1043014d4142cf86186a
57f81a5fcbd1fefd6ec3cdd525a85b707b4eead532c1b3092daafd88ee9268ec
89082fb05229826bc222f5d22c158235f025f0e6df67ff135a18bd899e13bb8f
e848603b7a73a88e3fe7bffa20e83397f5d1e93e77babb31473cc99e654a27b7
Domains
settings-win.data.microsoft.com
fe3cr.delivery.mp.microsoft.com
config.edge.skype.com
edge-consumer-static.azureedge.net
client.wns.windows.com
oneocsp.microsoft.com
edge.microsoft.com
omex.cdn.office.net
www.microsoft.com
copilot.microsoft.com
messaging.lifecycle.office.com
self.events.data.microsoft.com
go.microsoft.com
google.com
update.googleapis.com
ocsp.digicert.com
crl.microsoft.com
activation-v2.sls.microsoft.com
clients2.googleusercontent.com
www.bing.com
URLs
https://ecs.office.com/config/v2/office/outlook/16.0.16026.20146/production/cc?&clientid=%7bd61ab268-c26a-439d-bb15-2a0dedfca6a3%7d&application=outlook&platform=win32&version=16.0.16026.20146&msoversion=16.0.16026.20002&sdx=fa000000002.2.0.1907.31003&sdx=fa000000005.1.0.1909.30011&sdx=fa000000006.1.0.1909.13002&sdx=fa000000008.1.0.1908.16006&sdx=fa000000009.1.0.1908.6002&sdx=fa000000016.1.0.1810.13001&sdx=fa000000029.1.0.1906.25001&sdx=fa000000033.1.0.1908.24001&sdx=wa104381125.1.0.1810.9001&processname=outlook.exe&audience=production&build=ship&architecture=x64&language=en-us&subscriptionlicense=false&perpetuallicense=2019&licensecategory=6&licensesku=professional2019retail&osversion=10.0&osbuild=19045&channel=cc&installtype=c2r&sessionid=%7b8c7d9ceb-7ae6-4b2b-bd57-a8879251a290%7d&labmachine=false
https://omex.cdn.office.net/addinclassifier/officesharedentities
https://messaging.lifecycle.office.com/getcustommessage16?app=6&ui=en-us&src=bizbar&messagetype=bizbar&hwid=04111-083-043729&ver=16.0.16026&lc=en-us&platform=10%3a0%3a19045%3a2%3a0%3a0%3a256%3a1%3a&productid=%7b1717c1e0-47d3-4899-a6d3-1022db7415e0%7d%3a00411-10830-43729-aa720%3aoffice%2019%2c%20office19professional2019r_retail%20edition&clientsessionid=%7b8c7d9ceb-7ae6-4b2b-bd57-a8879251a290%7d&datapropertybag=%7b%22audience%22%3a%22production%22%2c%22audiencegroup%22%3a%22production%22%2c%22audiencechannel%22%3a%22cc%22%2c%22flight%22%3a%22ofsh6c2b1tla1a31%2cofcrui4yvdulbf31%2cofhpex3jznepoo31%22%7d
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:jyly0-hn5pzkktles67g9_dg3jyxyseivzfi4xl5538&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://files-link-private.s3.us-east-1.amazonaws.com/bb7216bd-1b75-4c21-b0ab-db8a7e65190a/b54100a2-f5aa-4300-a776-abbebdd0b4b2/purchaseorder-po%23202608459.vbs?x-amz-algorithm=aws4-hmac-sha256&x-amz-content-sha256=unsigned-payload&x-amz-credential=akia3ra4amkuzyjyc7v4%2f20260827%2fus-east-1%2fs3%2faws4_request&x-amz-date=20260827t054758z&x-amz-expires=604800&x-amz-signature=976d59abc9dc76407c2f9061e0321ed40fc102cd9e3e5aa8adc53a111fab8ad6&x-amz-signedheaders=host&x-amz-checksum-mode=enabled&x-id=getobject
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d251%2526e%253d1
https://update.googleapis.com/service/update2/json?cup2key=14:dv-tb5tbx-rv6cigtje3mrtyluadr8h15joz83wv_eg&cup2hreq=1cc67ce5d327690a893c737bdebeac9a431ab9c4ff0c95373cdbdb8d4922f92c
https://www.bing.com/api/shopping/v1/user/shoppingsettings
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
https://clients2.googleusercontent.com/crx/blobs/abe5cl6a_jaanxapcjclooga79zaaqm3tadaaxpzgbj_5tef2gcwgawlwvojctwjy-62xnz5nkplhywefhkfca7ve1mtom8zrfv598knndu2neqdltxpxs0ljjjkmozedq0axlka5z-i_mcpvgwijs_fx-_dkkqdwg3y/ghbmnnjooekpmoecnnnilnnbdlolhkhi_1_109_1_0.crx
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2191
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 6596
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10054
comments 0

Inside UpCrypter: How a Stealthy Loader Slips Past Defenses to Deliver RATs Worldwide

Key Takeaways

  1. Multi-Stage Attack Complexity. UpCrypter employs multi-stage attack chains with obfuscation, anti-analysis checks, and in-memory execution, making detection and analysis significantly more challenging than simple malware payloads.

  2. Phishing as Primary Vector. The primary attack vector remains phishing emails with personalized lures (voicemail and purchase order themes). Organizations must prioritize email security and user training as foundational defenses.

  3. Global and Expanding Threat. UpCrypter campaigns have demonstrated global reach affecting multiple industries including manufacturing, technology, healthcare, construction, and retail. Detection counts have doubled within two-week periods, indicating rapid expansion.

Gather up-to-date intel on UpCrypter: select sample analyses via ANY.RUN’s Threat Intelligence Lookup and explore to understand TTPs and collect IOCs for detection and response:

threatName:"UpCrypter"

UpCrypter Sandbox analyses found via TI Lookup UpCrypter Sandbox analyses found via TI Lookup

  1. Flexible RAT Deployment. UpCrypter's architecture enables deployment of multiple RATs (PureHVNC, DCRat, Babylon RAT) based on attacker objectives, making this malware adaptable to diverse attack scenarios.
  2. Advanced Evasion Techniques. The malware implements comprehensive anti-VM checks, anti-analysis processes, forensic tool detection, and behavioral obfuscation that actively resist both dynamic and static analysis techniques.

ANY.RUN’s Interactive Sandbox is not perplexed by UpCrypter's anti-evasion: analyze suspicious files and emails, view analysis sessions published by ANY.RUN's community.

See UpCrypter in action.

UpCrypter sample in the Sandbox UpCrypter sample detonated in the Sandbox

  1. Persistent Access Establishment. UpCrypter establishes registry-based persistence, ensuring continued access across system reboots and enabling long-term compromise for data exfiltration or secondary attack deployment.

What is UpCrypter Malware?

UpCrypter represents a modern evolution in malware loaders, blending heavy obfuscation, anti-analysis techniques, and in-memory execution to bypass traditional security tools. It uses JavaScript droppers, obfuscated PowerShell scripts, MSIL loaders, and direct in-memory execution to maintain stealth throughout the infection process. The threat is particularly dangerous because it implements advanced evasion techniques including anti-VM checks, anti-analysis scanning, and infrastructure-level reconnaissance before deploying final payloads.

Unlike standalone ransomware or infostealers, UpCrypter acts as a pipeline for deploying multiple RAT families, such as PureHVNC, DCRat, and Babylon RAT. These tools grant attackers full remote control over infected hosts, facilitating credential harvesting, keylogging, screen capture, and lateral movement within networks.

The loader's code is padded with junk data and strings to obscure its intent, making static analysis challenging. It supports dual delivery formats: plain text configurations and payloads hidden via steganography in image files, further complicating detection by antivirus scanners.

What makes UpCrypter particularly notable is its modular architecture, which allows attackers to deliver different RAT payloads based on their objectives and the target environment. The malware's persistence mechanism ensures that even after system reboots, the malicious code continues to execute through registry-based persistence techniques.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

UpCrypter Malware Victimology

UpCrypter campaigns exhibit broad victimology, targeting organizations across multiple sectors and geographies without apparent discrimination based on size or location. Since August 2025, attacks have primarily struck manufacturing, technology, healthcare, construction, retail, and hospitality industries. These sectors are attractive due to their reliance on email for business communications, making phishing a low-barrier entry point.

Geographically, the malware operates on a truly global scale, with infections reported in North and South America, Europe, Africa, South Asia, and broader Asia. No specific high-profile victims have been publicly named, but the campaign's volume — over 115,000 phishing emails in one week alone — suggests thousands of potential compromises.

Small to medium-sized businesses (SMBs) are particularly vulnerable, as they often lack advanced email filtering or employee training. Larger enterprises in targeted sectors face risks from supply-chain-like exposures, where initial footholds enable lateral movement to critical systems

How UpCrypter Functions

UpCrypter operates through a multi-stage attack chain that progressively loads additional components and implements evasion techniques:

Stage 1: JavaScript Dropper. Victims receive phishing emails with HTML file attachments or click malicious links leading to phishing pages. The HTML/JavaScript files use Base64 encoding and XOR operations to obfuscate redirect URLs. The script redirects victims to spoofed websites personalized with the target's email domain.

Stage 2: Initial Download. The phishing page downloads a ZIP archive containing a heavily obfuscated JavaScript file padded with large amounts of junk code. The page displays a message encouraging the victim to open the downloaded file immediately.

Stage 3: PowerShell Launch. The JavaScript creates a Shell.Application object and constructs a Base64-encoded PowerShell command. It executes PowerShell with "-ExecutionPolicy bypass" using ShellExecute with window style 0 to hide the console window.

Stage 4: Network Verification and Anti-Analysis. The Base64-decoded PowerShell payload sends a ping to google.com to verify internet connectivity. If the system cannot reach the internet, it forces a system restart. It then scans running processes for forensic tools, debuggers, and sandbox indicators including Wireshark, OllyDBG, Immunity Debugger, and others. If analysis tools are detected, the malware forces a system restart and exits.

Stage 5: MSIL Loader Download. Once all checks pass, the PowerShell script downloads an MSIL (Microsoft Intermediate Language) loader from a remote server. The data is dissected using "%x%" as a delimiter, decoded from character codes into raw MSIL, and executed directly in memory through .NET reflection, avoiding disk writes.

Stage 6: MSIL Loader Execution. The MSIL loader performs additional anti-VM and anti-analysis checks. It verifies persistent directories exist and creates them if necessary. It communicates with command and control servers to download additional components including DLL loaders and the final RAT payload.

Stage 7: RAT Deployment. The MSIL loader downloads and executes the final RAT payload (PureHVNC, DCRat, or Babylon RAT) directly in memory. The payload is embedded directly into PowerShell scripts without disk writes, maintaining operational stealth.

Stage 8: Persistence. The malware adds PowerShell execution commands to the registry at "HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run", ensuring the malicious code executes automatically upon system startup.

UpCrypter Sample Real-Time Analysis

ANY.RUN’s Interactive Sandbox supports UpCrypter’s detonation and dissection in spite of its anti-VM and anti-analysis techniques.

View an analysis session of an UpCrypter sample.

In most cases, the malware’s behavior demonstrates a number of TTPs and characteristic patterns.

An URL clicked in a phishing email triggers the download of a malicious file.

Malicious UpCrypter file masked as pdf Malicious UpCrypter file masked as pdf

The file is a heavily obfuscated JavaScript script (sometimes VBS), filled with redundant code to conceal the malicious logic.

Its main purpose is to assemble and execute the primary malicious payload in PowerShell.

UpCrypter payload in PowerShell UpCrypter payload in PowerShell

The main PowerShell payload, encoded in Base64 (PwBSs), performs network checks, anti-analysis routines, and prepares the environment for the loader’s execution.

It sends a ping request to google.com to check the internet connection; if it fails, the computer reboots.

UpCrypter pings internet connection to google.com UpCrypter pings internet connection to google.com

After passing all checks, the PowerShell script downloads the next-stage payload from a remote server as a text file containing character codes (sometimes disguised as an image).

It then extracts and decodes these codes into a raw MSIL loader.

UpCrypter payload encoded in text file UpCrypter payload encoded in text file

This stage repeats many of the previous steps and again relies on PowerShell execution.

A notable behavior is the launch of PowerShell commands from a registry key value to achieve persistence.

UpCrypter persistence mechanism UpCrypter persistence mechanism abusing WIN registry and PowerShell

Before downloading and executing the final malicious payload, the loader erases temporary artifacts and files to complicate detection and forensic analysis.

UpCrypter deletes files UpCrypter deletes files

Gathering Threat Intelligence on UpCrypter Malware

Threat intelligence is essential for defending against modern loaders like UpCrypter.

By aggregating indicators of compromise (IOCs) — such as malicious domains, hashes, and URLs — and mapping TTPs (tactics, techniques, procedures) to MITRE ATT&CK, defenders can detect new campaigns before they fully evolve.

High-quality threat intelligence enables:

  • Real-time enrichment of alerts with context about UpCrypter-related infrastructure
    • Faster triage and prioritization of true incidents over false positives
    • Proactive hunting for stealthy infections already in progress
    • Automated blocking of malicious URLs or domains in firewalls and proxies

In fast-moving phishing ecosystems, the freshness of threat intelligence is a decisive factor in stopping attacks before they scale.

Use ANY.RUN’s Threat Intelligence Lookup to search IOCs and behavior data linked to UpCrypter loader. Start from querying the threat name to find UpCrypter samples that ANY.RUN’s community of 500K professionals and 15K SOC teams has already analyzed. Study TTPs and gather indicators:

threatName:"UpCrypter"

UpCrypter sample analyses found via TI Lookup UpCrypter sample analyses found via TI Lookup

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

The global nature of UpCrypter campaigns and their targeted focus on critical business sectors indicate that organizations of virtually any size and industry can become victims. The threat is not limited to data theft or system compromise: UpCrypter serves as a foundation for ransomware attacks, lateral movement, intellectual property theft, and extended unauthorized network access.

Effective defense against UpCrypter requires layered security controls combining technical defenses, human-centered security awareness, and threat intelligence integration.

Threat intelligence plays an essential role in this defense strategy by providing indicators of compromise, attacker context, early warning capabilities, and operational guidance for incident response.

As attackers continue to refine their tactics and expand their campaigns, security teams must maintain vigilance, invest in continuous training, and adapt their defenses based on emerging attacker evolution.

Start gathering actionable threat intelligence on UpCrypter by signing up to ANY.RUN’s TI Lookup: protect your business with timely detection and response.

HAVE A LOOK AT

Lumma screenshot
Lumma
lumma
Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.
Read More
DeerStealer screenshot
DeerStealer
deerstealer
DeerStealer is an information-stealing malware discovered in 2024 by ANY.RUN, primarily targeting sensitive data such as login credentials, browser history, and cryptocurrency wallet details. It is often distributed through phishing campaigns and fake Google ads that mimic legitimate platforms like Google Authenticator. Once installed, it exfiltrates the stolen data to a remote command and control (C2) server. DeerStealer’s ability to disguise itself as legitimate downloads makes it particularly dangerous for unsuspecting users.
Read More
WannaCry screenshot
WannaCry
wannacry ransomware
WannaCry is a famous Ransomware that utilizes the EternalBlue exploit. This malware is known for infecting at least 200,000 computers worldwide and it continues to be an active and dangerous threat.
Read More
LockBit screenshot
LockBit
lockbit
LockBit, a ransomware variant, encrypts data on infected machines, demanding a ransom payment for decryption. Used in targeted attacks, It's a significant risk to organizations.
Read More
CryptoWall screenshot
CryptoWall
cryptowall
CryptoWall is a notorious ransomware family that emerged in early 2014 and rapidly became one of the most destructive cyber threats of its time. This malware encrypts victims' files using strong AES encryption, demands ransom payments in Bitcoin, and has generated hundreds of millions of dollars for cybercriminals.
Read More
Havoc screenshot
Havoc
havoc
Havoc is an advanced post-exploitation framework used by hackers to take control of a system once they've breached it. With Havoc, attackers can run commands remotely, inject malicious processes, and access sensitive data. It's often used in targeted attacks, allowing cybercriminals to stay hidden in a network while stealing information or launching further attacks. Its flexibility and ability to bypass detection make it a serious threat, especially in environments that rely on traditional security tools.
Read More