Zupdax is a modular Windows remote access trojan active since at least early 2014 and used in cyberespionage operations. It collects host information, downloads and executes plugins, and supports updating and removing itself. Its command-and-control communications use the UDT library over UDP; some configurations disguise this traffic as DNS communications. Zupdax commonly executes through DLL side-loading, including abuse of a legitimate McAfee SiteAdvisor executable. Modern variants use loading components closely matching those used by MyKLoadClient. Its network-message structures, command identifiers, debug messages, and plugin architecture share similarities with the older Redsip backdoor.
Zupdax has been associated with both PKPLUG activity and the Space Pirates toolkit, but it is not uniquely attributable to either threat cluster. It was deployed during the 2019–2020 Vatican intrusions and has also been identified in compromised Able Desktop software installers targeting organizations in Mongolia. Shared infrastructure connects it with other espionage malware, including Poison Ivy, HenBox, and Farseer, without establishing common ownership or exclusive attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The criminals also have access to the Zupdax backdoor: its modern variants use a similar MyKLoadClient execution scheme.
The criminals also have access to the Zupdax backdoor: its modern variants use a similar MyKLoadClient execution scheme.
Злоумышленники также имеют доступ к бэкдору Zupdax: его современные варианты используют аналогичную MyKLoadClient схему исполнения, однако код самого бэкдора берет начало в 2010 году и не может быть однозначно привязан к группе.
Злоумышленники также имеют доступ к бэкдору Zupdax: его современные варианты используют аналогичную MyKLoadClient схему исполнения, однако код самого бэкдора берет начало в 2010 году и не может быть однозначно привязан к группе.
Злоумышленники также имеют доступ к бэкдору Zupdax: его современные варианты используют аналогичную MyKLoadClient схему исполнения, однако код самого бэкдора берет начало в 2010 году и не может быть однозначно привязан к группе.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Группа Space Pirates маскирует свое ВПО под легитимное ПО
Space Pirates malware uses various algorithms to encrypt configuration data and payload.
Data transferred is encrypted using RC4 with the encryption key “Microsoft”... Network traffic is LZ-compressed and base64 encoded... usernames and passwords are encrypted and base64 encoded.
ВПО группы Space Pirates поддерживает работу с несколькими C2 и может обновлять список C2 через веб-страницы
Once installed, the main payload connects back to C2 server and sets up communication... It is installed as a service in the Windows System folder, and when run, it sets up communication with C2 server over HTTP.
The malware will in some configurations try to disguise this as legitimate traffic by connecting to port 53 (DNS) on the command & control server, as well as deliberately naming the C2 domains with the ns* (nameserver) prefix.
77 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor using UDT-over-UDP C2 with magic 0x12345678; collects host profiling immediately after connect. Supports plugin-based execution, C2 update, self-removal, and downloading/executing updates. Modern variants use a MyKLoadClient-like dropper/launcher chain (legit siteadv.exe + launcher + encrypted payload ok.obj), often launched via mrun (RC4 + reflective loading). Strong lineage to Redsip (Night Dragon-era) based on identical message structure/magic and command semantics.
Plugin-oriented backdoor that collects system information, executes additional payloads, updates its control server, and supports self-removal. Communicates using UDT over UDP and reflectively loads plugins. The researchers assess it as a redesigned version of Redsip and correct an earlier identification of an Able Desktop payload as Korplug.
Zupdax is cited as another malware family associated with PKPLUG activity, but the content provides no further functional detail.
Malware family referenced as sharing overlapping infrastructure with Farseer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.