Skip to content

Upatre

Upatre is a Windows malware family first observed in 2013 and best characterized as a lightweight downloader used to deliver additional payloads onto compromised hosts.

Upatre

Family profile

Upatre is a Windows malware family first observed in 2013 and best characterized as a lightweight downloader used to deliver additional payloads onto compromised hosts. It has been widely associated with the delivery of banking trojans and other financially motivated malware, including Dyre, Gameover Zeus, Dridex, Chthonic, and ransomware such as CryptoLocker and CryptoWall. Upatre became especially prominent in large-scale crimeware distribution chains and was at times one of the most prevalent downloader families observed in the wild.

Upatre has commonly been distributed through malicious email attachments in phishing campaigns, including weaponized Office documents and compressed executables. Some campaigns used embedded-document techniques in which a malicious Office macro dropped an Upatre executable contained inside an RTF object rather than downloading it directly from the internet, improving evasion against signature-based and behavioral defenses. Upatre has also been observed in exploit-kit-driven delivery chains, including activity linked to RIG.

Functionally, Upatre serves as an initial-stage malware component that retrieves and executes follow-on payloads. Reported variants have also been capable of stealing user information. The family is notable for frequent updates and iterative anti-analysis improvements. Documented evasion methods include a simple sandbox check based on Windows system uptime via GetTickCount, causing the malware to terminate on recently booted systems commonly used in automated analysis environments. More advanced variants have used heavy code obfuscation, custom string and network-data encoding, packed or multi-stage decryption routines, virtual-machine detection based on running-process checks, in-memory code loading, and code injection into legitimate Windows processes.

Some Upatre variants have also taken post-compromise actions to weaken host defenses and maintain execution. Reported behaviors include disabling multiple Windows security services and protections, suppressing security notifications, altering user access control behavior, and establishing persistence through autorun policy mechanisms. Certain samples masqueraded as legitimate software to reduce suspicion.

Upatre is part of the broader financially motivated malware ecosystem and has been repeatedly used as a staging mechanism in campaigns that ultimately enabled credential theft, banking fraud, spam distribution, and ransomware deployment. Its operational role as a compact, adaptable downloader and its long-running use in phishing-driven intrusion chains made it a significant component of mid-2010s cybercrime activity.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Initial Access
  • Persistence
  • Post Exploitation
  • Process Injection

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

MITRE ATT&CK

Upatre in ATT&CK

24 distinct techniques

Reporting

Research mentioning Upatre

Jul 13
Paloalto Researchcenter Historic

Upatre Continued to Evolve with new Anti-Analysis Techniques

Upatre, a malware downloader commonly spread through phishing emails, was observed using a simple anti-analysis technique to avoid detection in automated sandbox environments. The malware calls the Windows API GetTickCount and terminates if the infected system appears to have been running for less than roughly 12 minutes, a condition that often matches freshly booted virtual machines used for short-lived malware analysis. The evasion tactic can cause Upatre samples to appear benign because they never execute their malicious payload during analysis. Researchers reported a surge in new Upatre samples using the method and noted that the downloader is frequently used to fetch the Dyre banking Trojan, which steals credentials. Palo Alto Networks said its WildFire platform mitigates the trick by modifying the GetTickCount return value so the malware believes the host has been running for hours.

Dec 16
Eset Welivesecurity

Nemucod malware spreads ransomware Teslacrypt

TeslaCrypt emerged as a fast-moving ransomware family that encrypted both common user documents and game-related files, including saved games and Steam-related data, expanding its impact to PC gamers. Initial infections were linked to malicious email attachments and exploit kits such as Angler, which abused browser and plugin flaws including Adobe Flash CVE-2015-0311; later distribution was also tied to Sweet Orange and Nuclear via compromised websites. The malware deleted Volume Shadow Copies, contacted command-and-control infrastructure, and used ransom notes and recovery files to pressure victims into paying in Bitcoin. Later TeslaCrypt variants significantly hardened their cryptography and extortion workflow. Researchers reported that early versions falsely claimed to use RSA-2048 while actually relying on AES-CBC-256, with key material stored locally in files such as key.dat, allowing decryption in some cases and enabling Cisco Talos to release a recovery utility when the necessary keys were present. TeslaCrypt 2.0, however, adopted a stronger design using ECDH over secp256k1 with AES-256-CBC, moved key-related data into the Windows registry, generated unique Bitcoin addresses per victim, appended the .zzz extension to encrypted files, and replaced its interface with an HTML ransom page modeled on CryptoWall, making recovery without attacker-controlled key material far more difficult.

Oct 9
Paloalto Researchcenter Historic

Latest TeslaCrypt Ransomware Borrows Code From Carberp Trojan

Oct 6
Palo Alto Networks Unit 42

Ticked Off: Upatre Malware’s Simple Anti-analysis Trick to Defeat Sandboxes

Jul 18
Securelist

TeslaCrypt 2.0 disguised as CryptoWall | Securelist

Apr 27
Cisco Talos

Threat Spotlight: TeslaCrypt - Decrypt It Yourself - Cisco Blogs