UPX is a legitimate open-source executable packer used to compress and wrap binaries across multiple platforms, especially Windows and Linux. It is not itself malware, but it is widely used by malware authors as a packing layer to reduce file size, hinder static analysis, and evade signature-based detection. Security reporting frequently notes UPX-packed payloads across diverse malware families and intrusion sets, including Linux botnets and worms, Windows DLL implants, remote access trojans, brute-force malware, and espionage tooling. Observed examples include Rust-based Linux malware such as P2Pinfect, Golang malware such as GoBruteforcer, TeamTNT-associated ELF payloads, and Windows implants linked to campaigns aligned with UAC-0057 and Patchwork. In these cases, UPX serves as a defense-evasion mechanism rather than the primary malicious capability. Because UPX is a benign packer with substantial legitimate use, its presence alone is not sufficient to classify a file as malicious.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The decrypted payload is an ELF file packed with UPX, which is a known sample from TeamTNT, first seen in June 2020.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
A buffer overflow vulnerability exists in Trend Micro AntiVirus that may occur when the scanning engine processes a malformed UPX archived file. If a specially crafted, UPX packed executable is scanned by Trend Micro, this vulnerability may be triggered.
The executable which is dropped by both malicious documents is packed with UPX... All of the dropped payloads were compressed with a packer
The executable which is dropped by both malicious documents is packed with UPX.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A packer used to compress or obfuscate executables; in this content it is used to pack P2Pinfect client binaries for Linux and Windows.
A common executable packer used here to compress/obfuscate C++ DLL implants (e.g., SDXHelp.dll, DiagnExp.dll) to hinder static analysis and detection.
Public executable packer used to compress/obfuscate some loader and DLL stages (e.g., UPX-packed PE/DLL) to hinder static analysis and signature-based detection.
Executable packer used to compress/obfuscate the GoBruteforcer samples.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.