UPSTYLE

MITRE ATT&CK: S1164 View on attack.mitre.org

Aliases: UPSTYLE

First seen
2024-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
network-devices, linux
Profile updated
2026-07-07 13:13:21

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

UPSTYLE is a Python-based backdoor associated with exploitation of Palo Alto firewalls using CVE-2024-3400 in early 2024. UPSTYLE has only been observed in relation to this exploitation activity, which involved attempted install on compromised devices by the threat actor UTA0218.

Detection coverage

  • 2 YARA rules
  • 93 Sigma rules

Malware & tools used

  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Clear Linux or Mac System Logs (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Masquerading (attack-pattern)
  • File Deletion (attack-pattern)
  • Junk Data (attack-pattern)
  • Timestomp (attack-pattern)
  • One-Way Communication (attack-pattern)
  • Process Discovery (attack-pattern)
  • Event Triggered Execution (attack-pattern)
  • Python (attack-pattern)
  • Hide Infrastructure (attack-pattern)

Used by threat actors

  • Operation MidnightEclipse (campaign)

Exploited vulnerabilities

  • CVE-2024-3400 (vulnerability)

Detection rules

  • VOLEXITY_Apt_Malware_Py_Upstyle (yara-rule)
  • SEKOIA_Apt_Uta0218_Upstyle_Backdoor_Strings (yara-rule)

Reports & references

  • volexity.com — Zero Day Exploitation Of Unauthenticated Remote Code Execution Vulnerability In Globalprotect Cve 2024 3400 (report)
  • malpedia.caad.fkie.fraunhofer.de — Py.Upstyle (report)
  • Palo Alto Unit 42 — Cve 2024 3400 (report)
  • MITRE ATT&CK — S1164 (report)

External references