C&CMembers
C&C

Upatre C2 Cluster Exploits Freshly Allocated French IP and 16-Year-Old Domain

A follow-up infrastructure snapshot of an active Upatre dropper campaign surfaces a new C2 IP on a broadband block allocated just months ago, a dormant Venezuelan domain re-weaponised with a fresh TLS certificate, and three confirmed beacon URL paths. The update adds no new file samples but sharpens the hosting fingerprint considerably, revealing an operator actively managing detection exposure against US media-sector targets.

May 31, 2026, 08:41 (UTC+9)Last seenMay 31, 2026Severity92ByCTX TeamIOC9MITRE17RegionsUS

Since CTX Team's earlier coverage of this Upatre dropper campaign targeting US media-sector organisations, the infrastructure picture has sharpened considerably. The update adds no new file samples — the dropper payload itself remains unchanged — but surfaces one new C2 IP address, two new domains, and three confirmed URL-form beacon paths that together complete a hosting architecture the prior snapshot could only partially sketch.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence