UPSTYLE is a custom Python-based backdoor associated with exploitation of Palo Alto Networks PAN-OS devices, particularly activity tracked as Operation MidnightEclipse involving CVE-2024-3400. The malware appears to have been created specifically for that campaign. Reporting states the threat actor initially intended to install UPSTYLE after exploiting PAN-OS, but was unsuccessful in observed incidents after multiple exploit attempts; in those cases, the actor instead installed a cron job backdoor for persistence. UPSTYLE has also been referenced as a persistent backdoor that attackers could deploy in PAN-OS campaigns following successful exploitation of PAN-OS vulnerabilities, including scenarios discussed around CVE-2025-0110. Behavior described in the content includes retrieving a non-existent webpage from its command-and-control server and parsing commands from the resulting error logs to decode commands to a web shell. It also restores timestamps to original values after modification, indicating anti-forensics/timestomping behavior, and has masqueraded under filenames such as update.py. High-confidence infrastructure and indicators mentioned for UPSTYLE include hosting at 144.172.79[.]92 and nhdata.s3-us-west-2.amazonaws[.]com, and SHA256 3de2a4392b8715bad070b2ae12243f166ead37830f7c6d24e778985927f9caac. The content ties UPSTYLE to PAN-OS firewall compromise, with related attacker objectives including firewall reconfiguration, sensitive data exfiltration, and persistent access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Successful exploitation allows attackers to reconfigure firewalls, exfiltrate sensitive data, or deploy persistent backdoors like the UPSTYLE malware observed in prior PAN-OS campaigns.
Successful exploitation allows attackers to reconfigure firewalls, exfiltrate sensitive data, or deploy persistent backdoors like the UPSTYLE malware observed in prior PAN-OS campaigns.
Successful exploitation allows attackers to reconfigure firewalls, exfiltrate sensitive data, or deploy persistent backdoors like the UPSTYLE malware observed in prior PAN-OS campaigns.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
"Threat Hunting: Monitor for anomalous gNMI requests or unexpected cron job creation, indicators of UPSTYLE backdoor activity."
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A persistent backdoor malware referenced as being deployed on Palo Alto Networks PAN-OS devices after exploitation, enabling long-term unauthorized access (with noted hunting guidance including monitoring for unexpected cron job creation).
Malware that restores original timestamps after modifying files.
UPSTYLE is a custom Python-based backdoor developed specifically for exploitation of CVE-2024-3400 in Palo Alto Networks PAN-OS firewalls. It is designed to provide persistent remote access, execute commands, and exfiltrate data while evading detection by using legitimate log and CSS files for command and control and output exfiltration.
Malware that uses benign-looking filenames (e.g., update.py) to appear legitimate and evade scrutiny.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.