logo

Evolution Of Upatre Trojan Downloader

ID: d0b88d51-c8ab-56d8-9c15-90e91c1ff542

STIX ID: report--d0b88d51-c8ab-56d8-9c15-90e91c1ff542

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive Summary:** The report details the Upatre Trojan downloader campaign used to deliver banking malware (Dyreza, Zeus, Rovnix) via Cutwail spam and exploit kits, describing infection chains, evasion techniques (password-protected and nested attachments, randomized headers, encrypted downloads, SSL C2), C2 behavior (TCP port 40007), decryption routines, and network indicators including sample HTTP requests and hardcoded User-Agent strings (ENUPDATE, ONLYUPDATE, UPDATE).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.