Upatre is a Windows malware family first observed in 2013 and best characterized as a lightweight downloader used to deliver additional payloads onto compromised hosts. It has been widely associated with the delivery of banking trojans and other financially motivated malware, including Dyre, Gameover Zeus, Dridex, Chthonic, and ransomware such as CryptoLocker and CryptoWall. Upatre became especially prominent in large-scale crimeware distribution chains and was at times one of the most prevalent downloader families observed in the wild.
Upatre has commonly been distributed through malicious email attachments in phishing campaigns, including weaponized Office documents and compressed executables. Some campaigns used embedded-document techniques in which a malicious Office macro dropped an Upatre executable contained inside an RTF object rather than downloading it directly from the internet, improving evasion against signature-based and behavioral defenses. Upatre has also been observed in exploit-kit-driven delivery chains, including activity linked to RIG.
Functionally, Upatre serves as an initial-stage malware component that retrieves and executes follow-on payloads. Reported variants have also been capable of stealing user information. The family is notable for frequent updates and iterative anti-analysis improvements. Documented evasion methods include a simple sandbox check based on Windows system uptime via GetTickCount, causing the malware to terminate on recently booted systems commonly used in automated analysis environments. More advanced variants have used heavy code obfuscation, custom string and network-data encoding, packed or multi-stage decryption routines, virtual-machine detection based on running-process checks, in-memory code loading, and code injection into legitimate Windows processes.
Some Upatre variants have also taken post-compromise actions to weaken host defenses and maintain execution. Reported behaviors include disabling multiple Windows security services and protections, suppressing security notifications, altering user access control behavior, and establishing persistence through autorun policy mechanisms. Certain samples masqueraded as legitimate software to reduce suspicion.
Upatre is part of the broader financially motivated malware ecosystem and has been repeatedly used as a staging mechanism in campaigns that ultimately enabled credential theft, banking fraud, spam distribution, and ransomware deployment. Its operational role as a compact, adaptable downloader and its long-running use in phishing-driven intrusion chains made it a significant component of mid-2010s cybercrime activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Although the delivery mechanism was not observed during our analysis, Upatre typically arrives via an email link/attachment or through a compromised website.
The sample, 94a8b4b22dab4171edde5b1bafbf2f17dbe3c3c4c01335c36ba3b6e5d3635b83, was compiled six days after our Upatre sample and delivered the Chthonic banking trojan via RIG exploit kit.
The Upatre sample is not technically packed — in fact the unpacked payload is about a quarter the size — but it is protected by two decryption stages. The first stage uses a simple XOR and ROL encryption, while the second stage uses a variant of RC4.
This first part of the series focuses on the initial step in reversing the malware: unpacking.
Upatre.BI imports all system APIs manually by calling a routine getProcByHash.
The PE resource section also contains images of Google Chrome, so when the binary is placed on the target machine, it appears to be that of the Google Chrome web browser.
Launches a trusted Windows application msiexec.exe and injects code into its memory space using an undocumented technique
The intended domains are encrypted and only decrypted when the malware is ready to use them... the data sent in the POST request is encrypted using a custom encryption algorithm.
Recently, the authors of Upatre added a very simple anti-analysis measure in an attempt to defeat sandboxes, which dynamically analyze executables to identify malicious behavior.
The new anti-analysis trick involves using the Windows API GetTickCount... The code calls GetTickCount and compares the returned value to 0xAFE74... If GetTickCount returns a value less than 0xAFE74, Upatre determines that the system has been running for less than 12 minutes and exits.
To, evade detection, the newly observed variant enumerates the running processes on the host, generates a CRC32 hash of the process name...
It first checks the size of a Windows DLL before decrypting the second stage and jumping to it. CatSrv.dll Upatre.BI checks the catsrv.dll in the Windows system directory.
Recently, the authors of Upatre added a very simple anti-analysis measure in an attempt to defeat sandboxes, which dynamically analyze executables to identify malicious behavior.
The new anti-analysis trick involves using the Windows API GetTickCount... The code calls GetTickCount and compares the returned value to 0xAFE74... If GetTickCount returns a value less than 0xAFE74, Upatre determines that the system has been running for less than 12 minutes and exits.
Over the last six years there has been an increased shift by malware authors to secure their C&C communications using the SSL/TLS protocol to stymie detection and blend in with normal traffic.
Other notable functionality of this new version of the Upatre malware includes: Disables the following Windows services: Windows Security Center Internet Connection Sharing Windows Firewall Windows Defender Windows Update Windows Defender Network Inspection Service Disables Windows security notification balloons on Windows 7 and up Disables Internet Explorer Phishing Filter Disables Windows User Access Control Notifications
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as historical context tied to earlier developer tooling and compression usage.
Small downloader malware delivered via spam ZIP attachments that retrieves and executes Gameover Zeus, indirectly leading to CryptoLocker infection.
Stage-0 downloader malware used to retrieve and install additional payloads from hardcoded domains. This variant also collects host information, uses encrypted HTTP POST communications, employs VM/process-based evasion, disables multiple Windows security features and services, injects code into msiexec.exe, and establishes persistence via a registry Run policy key.
Downloader payload embedded in malicious documents and dropped via macro and RTF redirection as part of the Dyre infection chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.