logo

Cryptocurrency Lures & Pupy RAT: UTG-Q-010 Campaign

ID: 4d7d84fe-3a1b-5800-98ca-6e3a5ea4bedb

STIX ID: report--4d7d84fe-3a1b-5800-98ca-6e3a5ea4bedb

Feed Name: Cyble Blog

Threat Score
82/100

Date Published: 2024-10-24

Date Updated: 2026-07-17

...
...

UTG-Q-010, a financially motivated East Asian APT, conducted a spear-phishing campaign targeting cryptocurrency enthusiasts and HR personnel by distributing a ZIP containing a malicious LNK that decrypts and drops an XOR-obfuscated loader DLL (faultrep.dll). The loader performs sandbox/VM checks, verifies internet connectivity, downloads and decrypts an encrypted payload (Pupy RAT), and uses DLL sideloading and in-memory/reflective execution to evade detection; the report includes detailed technical analysis and IOCs (hashes, URLs, IP).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.