UPX is a widely used open-source executable packer and compressor rather than a malware family. It is frequently encountered in both benign software and malicious tooling because it reduces binary size and complicates static analysis until unpacked. Across intrusion reporting, UPX commonly appears as a packing layer applied to Windows DLL implants, Linux ELF payloads, Rust worms and botnet clients, Golang brute-force malware, and AutoIT backdoors. Threat actors and commodity malware operators use it as a straightforward obfuscation and defense-evasion measure, sometimes in unmodified public form and sometimes with altered headers or surrounding loaders to hinder automated unpacking. Its presence has been observed in malware associated with TeamTNT, P2PInfect, GoBruteforcer, and campaigns aligned with UAC-0057/UNC1151 and Dropping Elephant. UPX itself does not define the payload’s functionality; instead, it serves as a packing layer around other malware such as backdoors, worms, botnet components, and implants targeting Windows and Linux systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The decrypted payload is an ELF file packed with UPX, which is a known sample from TeamTNT, first seen in June 2020.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Tools such as Ultimate Packer for Executables (UPX) are used to obfuscate malware
Помимо anti-debug, anti-VM и шифрования, авторы CTF используют обфускацию кода (T1027) и пакинг (Software Packing, T1027.002).
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a common software packer encountered in CTF reverse-engineering tasks and malware analysis contexts.
A packer used to compress or obfuscate executables; in this content it is used to pack P2Pinfect client binaries for Linux and Windows.
A common executable packer used here to compress/obfuscate C++ DLL implants (e.g., SDXHelp.dll, DiagnExp.dll) to hinder static analysis and detection.
Public executable packer used to compress/obfuscate some loader and DLL stages (e.g., UPX-packed PE/DLL) to hinder static analysis and signature-based detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.