
Upatre Downloader Returns With Anti-Analysis Stack Shielding FTP C2
A fresh Upatre cluster detected on June 24, 2026 pairs FTP-based payload retrieval with layered sandbox evasion, debugger checks, and active security-tool disablement before any C2 contact. The sole attributable node sits inside a 2003-vintage Czech ISP netblock, drawing only seven flags from ninety-one detection engines.
Three Windows PE droppers surfaced in CTX Team's feed on June 24, 2026, carrying a threat label that many defenders might dismiss on sight: Upatre, a downloader family old enough to have been circulating when the Czech ISP subnet it now phones home to was first registered. That familiarity is precisely the risk. The current cluster — tracked as CTX4uky7ju34a — pairs the family's well-worn FTP-based payload retrieval with a layered anti-analysis stack that sequences time-based sandbox checks…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read