UPSTYLE
MITRE ATT&CK: S1164 View on attack.mitre.org
Aliases: UPSTYLE
- First seen
- 2024-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- network-devices, linux
- Profile updated
- 2026-07-07 13:13:21
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
UPSTYLE is a Python-based backdoor associated with exploitation of Palo Alto firewalls using CVE-2024-3400 in early 2024. UPSTYLE has only been observed in relation to this exploitation activity, which involved attempted install on compromised devices by the threat actor UTA0218.
Detection coverage
- 2 YARA rules
- 93 Sigma rules
Malware & tools used
- Deobfuscate/Decode Files or Information (attack-pattern)
- Clear Linux or Mac System Logs (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Masquerading (attack-pattern)
- File Deletion (attack-pattern)
- Junk Data (attack-pattern)
- Timestomp (attack-pattern)
- One-Way Communication (attack-pattern)
- Process Discovery (attack-pattern)
- Event Triggered Execution (attack-pattern)
- Python (attack-pattern)
- Hide Infrastructure (attack-pattern)
Used by threat actors
- Operation MidnightEclipse (campaign)
Exploited vulnerabilities
- CVE-2024-3400 (vulnerability)
Detection rules
- VOLEXITY_Apt_Malware_Py_Upstyle (yara-rule)
- SEKOIA_Apt_Uta0218_Upstyle_Backdoor_Strings (yara-rule)
Reports & references
- volexity.com — Zero Day Exploitation Of Unauthenticated Remote Code Execution Vulnerability In Globalprotect Cve 2024 3400 (report)
- malpedia.caad.fkie.fraunhofer.de — Py.Upstyle (report)
- Palo Alto Unit 42 — Cve 2024 3400 (report)
- MITRE ATT&CK — S1164 (report)