Urpage is a highly targeted threat actor distinguished by the use of InPage-themed lures and malware delivery targeting users of the Urdu and Arabic word processor InPage. The activity shows strong technical overlap with Bahamut, Confucius, and Patchwork through shared or closely related malware components, infrastructure patterns, and delivery methods, suggesting tool sharing, shared services, or a common development resource. Urpage is best characterized as a mobile- and document-focused espionage actor operating against users in South Asia and the broader Middle East, particularly around Kashmir- and Islam-related themes. Urpage has used malicious Android applications distributed through fake or spoofed websites masquerading as legitimate services and app-download portals. These Android implants have included Bahamut-like code and capabilities to collect device information, steal SMS messages and contacts, record audio, retrieve GPS location, and exfiltrate files including documents, media, geolocation data, and messaging-related data. One notable operation used a trojanized Threema-themed application that installed a modified version of the app and covertly captured screenshots of messages for exfiltration, indicating an emphasis on surveillance of secure communications. The actor has also delivered Windows malware through malicious RTF and InPage documents exploiting CVE-2017-8750 and CVE-2017-12824. These lures dropped VB backdoors and Delphi-based malware, often packaged in self-extracting archives that opened decoy content while installing the payload. Shared Delphi file-stealer functionality and related backdoor tradecraft connect Urpage activity to Confucius and Patchwork. Additional delivery mechanisms have included phishing-style websites, HTA downloaders, and decoy documents or images themed around Kashmir. Targeting patterns indicate an interest in users associated with Kashmir, Islamic services, and audiences in the Middle East and South Asia. No broad victimology has been publicly established, consistent with a narrowly scoped collection effort. The available evidence supports espionage as the dominant motivation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
A malicious InPage file that exploits CVE-2017-12824 and drops two files, one non-malicious, and one malicious VB backdoor with C&C referfile[.]com
A malicious RTF file that exploits the CVE-2017-8750 and drops a malicious VB backdoor with C&C appswonder[.]info
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Urpage is a threat actor group known for targeting users in the Middle East and South Asia, particularly those using Urdu and Arabic language tools. It employs a variety of malware, including Delphi and VB backdoors, and Android malware similar to Bahamut. Urpage uses fake websites to distribute malicious Android applications and exploits vulnerabilities in document files to deliver payloads. Its operations show significant overlap and tool-sharing with Bahamut, Confucius, and Patchwork.
Conducts targeted campaigns using malicious InPage documents, VB and Delphi backdoors, and Bahamut-like Android malware. Infrastructure also hosted phishing sites and exploit documents, with targeting indications tied to Kashmir and Middle East-themed lures.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.