
Upatre C2 Cluster Exploits Freshly Allocated French IP and 16-Year-Old Domain
A follow-up infrastructure snapshot of an active Upatre dropper campaign surfaces a new C2 IP on a broadband block allocated just months ago, a dormant Venezuelan domain re-weaponised with a fresh TLS certificate, and three confirmed beacon URL paths. The update adds no new file samples but sharpens the hosting fingerprint considerably, revealing an operator actively managing detection exposure against US media-sector targets.
Since CTX Team's earlier coverage of this Upatre dropper campaign targeting US media-sector organisations, the infrastructure picture has sharpened considerably. The update adds no new file samples — the dropper payload itself remains unchanged — but surfaces one new C2 IP address, two new domains, and three confirmed URL-form beacon paths that together complete a hosting architecture the prior snapshot could only partially sketch.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read