C&CMembers
C&C

Upatre Downloader Returns With Anti-Analysis Stack Shielding FTP C2

A fresh Upatre cluster detected on June 24, 2026 pairs FTP-based payload retrieval with layered sandbox evasion, debugger checks, and active security-tool disablement before any C2 contact. The sole attributable node sits inside a 2003-vintage Czech ISP netblock, drawing only seven flags from ninety-one detection engines.

Jun 24, 2026, 13:54 (UTC+9)Last seenJun 24, 2026Severity100ByCTX TeamIOC8MITRE13

Three Windows PE droppers surfaced in CTX Team's feed on June 24, 2026, carrying a threat label that many defenders might dismiss on sight: Upatre, a downloader family old enough to have been circulating when the Czech ISP subnet it now phones home to was first registered. That familiarity is precisely the risk. The current cluster — tracked as CTX4uky7ju34a — pairs the family's well-worn FTP-based payload retrieval with a layered anti-analysis stack that sequences time-based sandbox checks…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence