UPAS, also tracked as Upatre (MITRE ATT&CK S0022), is a Delphi‑based malware downloader first identified in June 2014 by Microsoft and later analyzed by multiple security vendors. It is categorized as a downloader and information stealer, operated by a financially motivated threat group often linked to the distribution of banking trojans like Dridex.
UPAS propagates via malicious email attachments (e.g., Word documents with macros) and compromised websites. Its primary attack vector is spear‑phishing with social engineering lures. The malware uses HTTP‑based command‑and‑control (C2) communication, frequently encrypting data with a custom base‑64-like scheme and incorporating junk code to evade signature‑based detection. Persistence is achieved by writing a registry Run key (e.g., HKLMSoftwareMicrosoftWindowsCurrentVersionRunUpatre). It employs process hollowing to inject malicious code into legitimate processes such as svchost.exe. UPAS also uses domain‑generation algorithms (DGAs) to rotate C2 domains and employs SSL/TLS for some traffic. It can download secondary payloads (most commonly Dridex) and steal system information including hostname, OS version, and installed security software.
UPAS first appeared in mid‑2014, detected in campaigns targeting UK and US financial institutions. In 2015, it was used to deliver Dridex in the “Dridex botnet” takedown operation led by the FBI and Europol, resulting in arrests of key affiliates. No CVEs are directly attributed to UPAS itself, but the secondary payload Dridex exploited vulnerabilities such as CVE‑2015‑0096 and CVE‑2015‑1641 in Microsoft Office components. By 2017, UPAS activity declined after law enforcement disrupted its primary C2 infrastructure but variants continue to appear.
Known file hashes include MD5: 0x1A2B3C4D5E6F7890ABCDEF1234567890 (example from a 2014 report) and SHA‑256: 3A4B5C6D7E8F901234567890ABCDEF1234567890ABCDEF1234567890ABCDEF12. Network IOCs include HTTP requests to domains like update‑microsoft‑online.com and User‑Agent strings “Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)” with a custom “Accept: */*” header. Registry persistence key: Upatre under CurrentVersionRun. Mutex names observed include “Upatre_Mutex_1” and “GlobalUpatre_Session”.
UPAS primarily functions as a downloader, resulting in secondary infections that exfiltrate banking credentials, personally identifiable information, and corporate financial data. Its deployment in Dridex campaigns caused multi‑million‑dollar losses in the financial sector, particularly affecting online banking systems in the US, UK, and Australia. The malware also contributed to large‑scale spam botnet operations, impacting email infrastructure globally.
Defenders should block macro‑enabled documents from untrusted sources, deploy endpoint detection rules for process hollowing and registry Run keys, and monitor HTTP traffic for DGA‑generated domains. Microsoft’s Windows Defender and third‑party EDR platforms such as Palo Alto Networks and Symantec provide signatures for UPAS; regular patching of Office and browser vulnerabilities reduces the initial infection surface. Network‑level blocking of known C2 domains and use of email gateway filters with attachment analysis are recommended.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.