Introduction
Routine business emails are increasingly becoming conduits for malware, raising concerns across organizations worldwide. Attackers are cleverly disguising harmful content within seemingly innocent emails, such as those related to damaged deliveries or refund requests, enticing recipients to unknowingly download malicious files. These emails, often appearing legitimate at first glance, redirect users to fake download pages hosting malware-laden ZIP archives.
Regional Targeting and Language Adaptation
Between July and August 2026, a wave of email attacks targeted organizations using messages written in Japanese and Korean. These emails, designed to instill urgency, dealt with issues like product damage and shipping discrepancies. Upon analysis by ITOCHU Cyber & Intelligence Inc., it was discovered that these malicious campaigns were not limited to a single language. The inclusion of Vietnamese, English, Chinese, Japanese, and Korean suggests a broader regional focus, potentially affecting East and Southeast Asia.
The emails often mimic standard business communication, tricking employees into clicking links that lead to deceptive sites masquerading as document or video-sharing platforms. These sites often claim that the file is too large for a preview, urging users to download a ZIP file, which is the malware’s delivery mechanism.
The Hidden Dangers of Malware Payloads
The ramifications of downloading these files are severe. Victims can inadvertently install PureRAT, a remote access tool, or PureLogs, an information-stealing malware. These tools compromise sensitive business data and enable attackers to maintain persistent access to the infected systems. Attackers continuously adapt the software used in these campaigns, complicating detection efforts by cybersecurity teams.
The superficial appearance of legitimacy in these emails is bolstered by technical tactics. For instance, some archives contain executable files disguised with double extensions to resemble PDFs, making them seem innocuous. These files typically pair an executable with a DLL, employing legitimate software to load malicious content, which can bypass some security measures due to file-size limitations.
Protective Measures and Future Outlook
To combat these threats, organizations should implement robust verification processes for unexpected emails, particularly those requesting refunds or containing download links. Security teams are advised to scrutinize any driver installations, new services, or scheduled tasks for signs of compromise. Monitoring email headers can also reveal inconsistencies, such as mismatched sender addresses and reply-to fields, hinting at potential phishing attempts.
Combining vigilant email inspection with behavioral monitoring and prompt reporting by employees can fortify defenses against these sophisticated attacks. As attackers refine their methods, organizations must remain proactive, ensuring that even mundane business communications are scrutinized for potential threats.
