Uplo Exfiltrator is a data exfiltration tool associated with the Mysterious Elephant APT. It is described as targeting specific file types and uploading them to attacker-controlled C2 servers. Reporting states that the malware is used in intrusions against government and foreign affairs entities in the Asia-Pacific region, with a strong focus on South Asia, including Pakistan, Bangladesh, Afghanistan, Nepal, and Sri Lanka. Uplo Exfiltrator is specifically noted as one of the modules used to exfiltrate WhatsApp communications from compromised hosts, capturing files exchanged through WhatsApp Desktop. It has been referenced alongside another module, Stom Exfiltrator, as part of Mysterious Elephant’s broader data-theft tooling. High-confidence behavioral detail in the provided content is limited to selective file targeting and upload to C2, with a stated focus on stealing WhatsApp-shared documents and related files from infected systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uplo Exfiltrator is a module designed to capture and exfiltrate files exchanged via WhatsApp from compromised hosts.
File exfiltration utility that enumerates and uploads targeted document/archive/certificate/contact/image extensions; uses XOR deobfuscation for C2 paths and recursive depth-first traversal to locate and stage sensitive files (including WhatsApp-shared content).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.