Upatre
- First seen
- 2013-01-01 00:00:00
- Malware type
- downloader, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:33:47
- Profile updated
- 2026-07-07 15:25:12
Targeted industries: financial-services
Context
Upatre is primarly a downloader. It has been discovered in 2013 and since that time it has been widely updated. Upatre is responsible for delivering further malware to the victims, in specific upatre was a prolific delivery mechanism for Gameover P2P in 2013-2014 and then for Dyre in 2015.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Upatre_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Upatre (report)
- secrary.com — Upatre (report)
- johannesbader.ch — Win32 Upatre Bi Part 1 Unpacking (report)
- marcoramilli.com — Is Upatre Downloader Coming Back (report)
- Palo Alto Unit 42 — Ticked Off Upatre Malwares Simple Anti Analysis Trick To Defeat Sandboxes (report)
- researchcenter.paloaltonetworks.com — Unit42 Upatre Continues Evolve New Anti Analysis Techniques (report)