Attackers Are Turning Everyday Business Emails Into Malware Delivery Machines
A 2026 email campaign used damage and refund lures to deliver PureRAT and PureLogs via fake download sites.
ITOCHU Cyber & Intelligence reported a July–August 2026 campaign that emailed Japanese and Korean organizations about damaged goods, shipping problems, and refunds. Links led to multilingual fake document-sharing or video sites that offered ZIP archives hiding executables, including double-extension files and a malicious DLL loaded by a Microsoft-signed program. Loaders varied, including bundled Python, a modified Donut loader, and in-memory execution, with persistence through startup shortcuts, scheduled tasks, or the registry. Payloads were PureRAT, a remote access tool, and PureLogs, an infostealer collecting browser data, Discord information, screenshots, and files; one variant used a signed vulnerable driver to kill security processes.
- July–August 2026 emails used Japanese and Korean damage and refund lures.
- Links opened fake document or video sites that pushed ZIP downloads.
- Chains used double extensions, DLL side-loading, Donut, and in-memory code.
- Payloads were PureRAT and PureLogs, stealing browser, wallet, and chat data.
- Persistence used startup items, tasks, or the registry; a driver killed defenses.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | bdp.edu.vn | 68[.]lol PureLogs command-and-control infrastructure Domain bdp[.]edu[.]vn PureLogs command-and-control infrastructure Domain pure |
| domain | cloudflare.carriernetworks.top | mp4/views/PqsTVwXyZatii Fake video-viewing lure URL hxxps://cloudflare[.]carriernetworks[.]top/?sharingcenterDelivery_Unboxing_Verification.MP4 Fake v |
| domain | customerreviewproduct.com | d7c89907eeff77081d021d10d Malware-download lure URL hxxps://customerreviewproduct[.]com/Complete_Unboxing_And_Damage_Inspection.mp4/views/iOpLkJh |
| domain | customersrespondedpositively.com | p4/views/iOpLkJhGfDsAtp Fake video-viewing lure URL hxxps://customersrespondedpositively[.]com/Complete_Unboxing_And_Damage_Inspection.mp4/views/PqsTVwX |
| domain | documentcloudlink.com | xczcczlkcjaslda Malicious document-sharing lure URL hxxps://documentcloudlink[.]com/Complete_Unboxing_And_Damage_Inspection.mp4/views/mxqvczn |
| domain | drbox.august-brokers.co.nz | c1119bb8cc67a85a9ac9aeaca Malware-download lure URL hxxps://drbox[.]august-brokers[.]co[.]nz/download.php/Package_Condition_Recordingmp4?f=5331793 |
Full article1,028 words · extracted from cybersecuritynews.com · click to collapse
Attackers are turning routine business complaints into malware traps. A message about a damaged delivery or refund request can look ordinary, yet one click leads employees to a fake download page and a harmful ZIP archive.
The campaign targeted organizations with Japanese and Korean messages between July and August 2026. Product damage, shipping problems, and exchange requests created urgency, while links appeared to host documents or videos.
Analysts at ITOCHU Cyber & Intelligence Inc. identified the activity and found pages offering Vietnamese, English, Chinese, Japanese, and Korean. Those language choices suggest the operation could extend across East and Southeast Asia.
The impact goes beyond a bad attachment. Victims can receive PureRAT, a remote access tool, or PureLogs, an information stealer. Both pose risks to sensitive business data and give attackers ways to maintain access.
ITOCHU Cyber & Intelligence Inc. said in a report shared with Cyber Security News (CSN) that the campaign repeatedly changed the software used to install its malware. Simple file-based blocking may miss variants, especially when busy teams handle routine customer correspondence.
Turning Business Emails Into Malware Delivery Machines
The lures sound like normal business follow-up. Recipients are told an item arrived damaged, a recording is available, or a refund needs review. The message directs them to a site disguised as a document-sharing or video-viewing service.
The landing page claims a file is too large to preview and asks visitors to download a ZIP archive. Some pages change language using browser settings and location, while mobile visitors see a notice that prevents the download, narrowing exposure to inspection.
.webp)
This resembles earlier weaponized archive malware attacks, where an archive hides an executable behind a familiar document name. Here, one sample used a double extension to make an EXE file look like a PDF.
The archives generally pair the executable with a DLL. One sample used a legitimate Microsoft-signed program to load a malicious DLL, which was hidden and padded with unnecessary data.
That extra bulk could frustrate security tools with file-size limits, allowing the infection chain to proceed before alarms reach the security team.
.webp)
Email headers offered clues. The visible sender looked like a support address, but Reply-To pointed to an unrelated Outlook or Hotmail account. Shared identifiers and a common mailer format suggested the messages came from the same delivery environment.
Organizations should verify unexpected refund requests through a separate, trusted channel before opening links. Filters can flag suspicious sharing sites, while staff should report unsolicited complaints that require downloading an archive.
Changing Loaders Hide Data Theft
Once opened, the files launch a layered infection chain. Researchers observed bundled Python software, a modified Donut loader, and code that runs in memory, with each route designed to conceal the final payload.
Variants establish persistence through Startup shortcuts, scheduled tasks, or Registry entries. Others attempt to weaken Windows scanning and logging, while one uses a signed but vulnerable driver to kill security-product processes.
This echoes trusted driver abuse attacks, where attackers exploit high-level system access to silence defenses. Security teams should investigate unexpected driver installations, new services, scheduled tasks, and failed security processes.
PureRAT reports operating-system details, active windows, user names, security products, webcam status, and screenshots to its control server. It can steal information from browsers, cryptocurrency wallets, and messaging applications, making the initial email a gateway to wider exposure.
.webp)
PureLogs collects browser cookies and profiles, Discord data, screenshots, and file-search results. The final malware remains recognizable across samples, but changing loaders make detection based only on known file hashes unreliable.
Defenders should block the listed indicators, watch for archives containing disguised executables, and review alerts for DLL side-loading and persistence changes.
Recent fake file-sharing phishing campaigns show why trusted-looking portals deserve the same scrutiny as unexpected email attachments.
Combining email checks, behavior monitoring, and quick employee reporting offers stronger protection than any single file signature. A damage claim may be normal business traffic, but a surprise download request deserves closer attention.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| URL | hxxps://sharedocumentsystem[.]com/Full_Unboxing_Process_Inspection_Record_333_2026.docx/views/xlqpmzncvaret | Malicious document-sharing lure |
| URL | hxxps://shareddocumentdrivehub[.]com/Full_Unboxing_Process_Inspection_Record_333_2026.docx/views/xlqpmvcznaert | Malicious document-sharing lure |
| URL | hxxps://globaldocumentsharingcenter[.]com/Full_Unboxing_Process_Inspection_Record_333_2026.docx/views/zxczcczlkcjaslda | Malicious document-sharing lure |
| URL | hxxps://documentcloudlink[.]com/Complete_Unboxing_And_Damage_Inspection.mp4/views/mxqvcznplrtei | Fake video-viewing lure |
| URL | hxxps://drive[.]careernetwork[.]co[.]nz/download.php/Complete_Unboxing_And_Damage_Inspection?f=6d90494c1119bb8cc67a85a9ac9aeaca | Malware-download lure |
| URL | hxxps://drbox[.]august-brokers[.]co[.]nz/download.php/Package_Condition_Recordingmp4?f=5331793d7c89907eeff77081d021d10d | Malware-download lure |
| URL | hxxps://customerreviewproduct[.]com/Complete_Unboxing_And_Damage_Inspection.mp4/views/iOpLkJhGfDsAtp | Fake video-viewing lure |
| URL | hxxps://customersrespondedpositively[.]com/Complete_Unboxing_And_Damage_Inspection.mp4/views/PqsTVwXyZatii | Fake video-viewing lure |
| URL | hxxps://cloudflare[.]carriernetworks[.]top/?sharingcenterDelivery_Unboxing_Verification.MP4 | Fake video-preview lure |
| IP address | 103[.]153[.]74[.]201 | Email delivery infrastructure |
| IP address | 103[.]82[.]26[.]183 | Email delivery infrastructure |
| IP address | 103[.]82[.]20[.]17 | Email delivery infrastructure |
| IP address | 103[.]179[.]189[.]169 | Email delivery infrastructure |
| IP address | 103[.]179[.]188[.]9 | Email delivery infrastructure |
| IP address | 103[.]179[.]188[.]216 | Email delivery infrastructure |
| IP address | 103[.]179[.]188[.]236 | Email delivery infrastructure |
| IP address | 103[.]82[.]20[.]60 | Email delivery infrastructure |
| IP address | 103[.]153[.]75[.]131 | Email delivery infrastructure |
| File SHA-256 | 2e05d97ed7bfabea8f7370ba627e0705ec2c0fbf3974b39437e9d95d45d1a76d | Full_Unboxing_Process_Inspection_Record_2026_1412621.pdf.exe, PureRAT |
| File SHA-256 | e55412555b4699c6d3ce2ac60df81eb1ee0d5aa412a303555c8f64037d5633d0 | AppVIsvSubsystems64.dll, PureRAT |
| File SHA-256 | c1a2b48d4f639b46cf6cde8322666f0991531ef32ffe571140418ae40342ffe8 | PureRAT payload |
| File SHA-256 | 8cd271f946d84423c554992eb0176be395cdd7bf6179efe1822759d019c94f34 | Complete_Unboxing_And_Damage_Inspection.exe, Type 1 |
| File SHA-256 | eb20fb4e1de2844717270e600af05abac06b359be711eabf14a3d91bfbf966e6 | AppVIsvSubsystems32.dll, Type 1 |
| File SHA-256 | ad0c3182b18b5d7ba8771d830f4d51b4ada7e26f8d05223f4379e6312aba65fa | PureLogs, Type 1 |
| File SHA-256 | 2e05d97ed7bfabea8f7370ba627e0705ec2c0fbf3974b39437e9d95d45d1a76d | Full_Unboxing_Process_Inspection_Record_9862_2026.exe, Type 2-1 |
| File SHA-256 | 9e54486f204d8c9ff9c539c5b2119b79a6da21e3dfdb7f51ee8ebba62f851174 | AppVIsvSubsystems64.dll, Type 2-1 |
| File SHA-256 | af4ee79582992e348a8739579da478d50daccbaa6ec97420311916a2ac0fc503 | PureLogs, Type 2-1 and Type 2-2 |
| File SHA-256 | afdb4a8384812e907a73b59df0fb303af2ba94994b5f4bbb66a51ce2b04e7c32 | Full_Unboxing_Process_Inspection_Record_9862_2026.exe, Type 2-2 |
| File SHA-256 | 1b5cf526a28bae9283acf91b2c0ccae3163d24706e40d9a0aea38c4b79e65d36 | AppVIsvSubsystems64.dll, Type 2-2 |
| File SHA-256 | 567fc6e35bb45a6ecf5d870e454c813613032078a5ba01fcd374544930598703 | propsys_1f520a24.cache, Type 2-2 |
| File SHA-256 | 719f689b34f47be8ca105ce8484948474dafde0e106bab599e4a89326070c3d0 | Delivery_Unboxing_Verification_Details.exe, Type 3 |
| File SHA-256 | aee2aefbc73dbf5f65e455ef18e74e158290e21803bf3dd64a05d087bfaceb18 | uxtheme.dll, Type 3 |
| File SHA-256 | 5ab36c116767eaae53a466fbc2dae7cfd608ed77721f65e83312037fbd57c946 | BootRepair.sys, Type 3 |
| File SHA-256 | afd31f096c93776888454e1321654477cfd97eb0c6a75bea624d8f7d891e0a61 | PureLogs, Type 3 |
| Domain | shareddocumentdrivehub[.]com | Malware-delivery infrastructure |
| Domain | globaldocumentsharingcenter[.]com | Malware-delivery infrastructure |
| Domain | pixeldrain[.]com | File-delivery service observed in campaign |
| Domain | tirakian[.]com | PureRAT command-and-control server |
| Domain | logs[.]uvexio[.]com | PureLogs command-and-control infrastructure |
| Domain | tea[.]vexexo[.]com | PureLogs command-and-control infrastructure |
| Domain | trump2[.]1368[.]lol | PureLogs command-and-control infrastructure |
| Domain | bdp[.]edu[.]vn | PureLogs command-and-control infrastructure |
| Domain | pure26[.]myftp[.]org | PureLogs command-and-control infrastructure |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.