When a Purchase Order Hides Malware: Understanding Sophisticated Fileless Malware Attacks
Cyberattacks are becoming increasingly sophisticated. While phishing emails remain one of the most common ways attackers gain initial access to organizations, today’s threats are designed to go far beyond simply tricking users into clicking a malicious link.
A recent campaign analyzed by Fortra demonstrates how attackers are combining phishing, multiple layers of obfuscation, scripting tools, and fileless malware techniques to evade traditional security controls.
The campaign began with what appeared to be a routine business email containing a purchase order. However, behind the seemingly legitimate attachment was a multi-stage malware infection designed to remain hidden and make detection significantly more difficult.
For organizations, this serves as an important reminder: email security is no longer just about blocking spam and known malware. Organizations need advanced protection capable of identifying sophisticated and evolving threats.
How the Attack Begins
The attack starts with a phishing email designed to look like a legitimate business communication.
The malicious attachment is packaged as a TAR archive and disguised as a purchase order. This type of business-themed lure can be particularly effective because employees may regularly receive purchase orders, invoices, and other documents as part of their daily responsibilities.
Once the recipient opens the attachment and executes the malicious script, the attack moves to the next stage.
This highlights an important security challenge: the email itself may not immediately appear malicious. The real threat may be hidden inside the attachment and only become active after the user interacts with it.
Five Layers Designed to Hide the Attack
According to Fortra’s analysis, the campaign uses five distinct layers of obfuscation.
In simple terms, attackers deliberately make their code difficult for security tools and analysts to understand.
The attack uses:
1. Obfuscated JScript
The first stage uses JScript with strings and variables that are deliberately difficult to interpret. Some legitimate-looking or decoy code is also included to make analysis more challenging.
2. Hidden PowerShell Execution
The JScript is used to hide the actual PowerShell command and launch PowerShell in a way intended to reduce visibility.
PowerShell is a legitimate Windows tool, but attackers frequently abuse it to execute malicious code.
3. Encoded Malware
The next stage uses additional encoding to prevent the malicious PowerShell loader from appearing as readable code.
This helps the attack avoid simple security checks that rely on identifying known malicious strings.
4. Payload Fragmentation
The malware is broken into many separate pieces and stored across process environment variables. These fragments are later reassembled during execution.
This technique makes it more difficult for security tools to identify the complete malicious payload.
5. In-Memory Execution
The final stage is loaded directly into memory rather than being written to the computer as a traditional executable file.
This is a key characteristic of fileless malware.
Because there may be little or no traditional executable file left on the disk, security teams cannot rely only on conventional file-based detection methods.
Why Fileless Malware Is a Serious Concern
Traditional malware often leaves behind files that security solutions can scan and identify.
Fileless malware takes a different approach.
Instead of relying on a conventional executable stored on disk, attackers can abuse legitimate tools and processes already available on the system, such as scripting engines and PowerShell.
This can make attacks more difficult to detect and investigate.
If the attack succeeds, the threat actor may be able to:
- Steal user credentials
- Exfiltrate sensitive business information
- Deliver additional malware
- Move further through the organization’s environment
- Potentially support ransomware or other follow-on attacks
The impact can extend beyond the initial compromised device, potentially resulting in data loss, operational disruption, financial damage, regulatory consequences, and reputational harm.
Why Traditional Email Security May Not Be Enough
This campaign demonstrates why organizations need to think beyond traditional email filtering.
An attacker may use:
- A convincing business-related email
- A seemingly legitimate purchase order
- A compressed or archived attachment
- Obfuscated scripts
- Legitimate system tools
- Multiple layers of encoded payloads
Each layer is designed to make detection more difficult.
Even if an email does not contain an obvious malicious executable, it may still represent the first step in a sophisticated attack.
Organizations therefore need a security strategy that can examine email content, attachments, links, and sender behavior before users interact with potentially dangerous content.
How Mimecast Can Help Strengthen Email Security
Organizations need a multi-layered approach to protect employees from sophisticated email-based threats.
Mimecast Targeted Threat Protection provides multiple security capabilities designed to defend against targeted phishing and advanced email threats.
Mimecast Attachment Protect
Attackers often use malicious attachments as the starting point for an attack.
Mimecast Attachment Protect helps protect users from weaponized attachments by performing security checks and preemptively sandboxing suspicious files before they reach users. It can also rewrite attachments into a safe format, helping organizations reduce the risk associated with malicious files.
This type of protection is particularly relevant to campaigns that use business-themed attachments to deliver malware.
Mimecast URL Protect
Phishing campaigns may also use malicious links to redirect users to websites that deliver malware or attempt to steal credentials.
Mimecast URL Protect scans URLs in incoming email and checks destinations in real time. Suspicious or malicious destinations can be blocked, helping prevent users from accessing dangerous websites.
Mimecast Impersonation Protect
Attackers often rely on social engineering and impersonation to make phishing emails appear trustworthy.
Mimecast Impersonation Protect analyzes inbound email for indicators of impersonation and social engineering. Suspicious messages can be blocked, quarantined, or presented with warnings, helping organizations reduce the risk of targeted phishing and business email compromise.
Building a Stronger Defense Against Sophisticated Phishing
No single security control can stop every cyberattack.
Organizations should combine advanced email security with other security practices, including:
- Regular employee security awareness training
- Multi-factor authentication
- Endpoint and identity monitoring
- Strong vulnerability management
- Network and process monitoring
- Regular backup and recovery testing
- Continuous threat detection and response
Security teams should also pay attention to unusual process activity, suspicious PowerShell behavior, and unexpected script execution.
The Fortra research highlights how attackers are increasingly investing in techniques that make malware harder to detect and investigate. This means organizations need to continuously improve their ability to detect threats across email, endpoints, identities, and the broader environment.
A phishing email may look like an ordinary business request, but it can be the starting point for a highly sophisticated cyberattack.
The campaign analyzed by Fortra demonstrates how attackers can combine a convincing email lure with malicious attachments, multiple layers of obfuscation, scripting tools, and fileless execution to evade traditional detection methods.
For businesses, the message is clear:
Don’t assume an email is safe simply because it looks legitimate.
Advanced email security can help organizations identify and block threats before they become a larger security incident.
With capabilities such as Mimecast Targeted Threat Protection, organizations can strengthen their defenses against malicious attachments, dangerous URLs, and impersonation-based phishing attacks, helping protect users from threats that may otherwise become the first step in a much larger compromise.
Bulwark Technologies helps organizations strengthen their cybersecurity posture with solutions from leading global cybersecurity technology providers. Contact our team to learn more about Mimecast and advanced email security solutions for your organization.

