Zupdax is a long-running Windows remote access trojan/backdoor active since at least 2014 and repeatedly observed in Asia-focused cyber-espionage operations. It has been associated with intrusion clusters including PKPLUG and Space Pirates, and has also been reported in compromises targeting Catholic and Vatican-linked organizations. Reporting has linked its use to activity aligned with Chinese strategic interests or Chinese-speaking operators, although the malware itself is not uniquely attributable to a single threat actor.
Zupdax is used for persistent remote access and post-compromise control. Modern variants commonly rely on DLL sideloading for execution, often abusing legitimate signed software components in a loader chain similar to MyKLoadClient. It communicates with command-and-control infrastructure using the UDT library over UDP, and some configurations disguise traffic to resemble DNS by using port 53 and nameserver-like host naming conventions. Technical reporting also describes a structured command protocol and plugin-oriented design, with some researchers assessing Zupdax to be a redesign or descendant of the older Redsip backdoor.
Operationally, Zupdax appears in espionage campaigns alongside other established backdoors such as PlugX, Poison Ivy, ShadowPad, and 9002. Observed victimology includes government, religious, aerospace, IT, and energy-sector organizations, particularly in Southeast Asia, Russia, Georgia, Mongolia, and entities connected to the Holy See. Its recurring use with trusted signed binaries and sideloading-based execution reflects an emphasis on stealth, defense evasion, and durable access in targeted intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Other malware families that have been seen relating to PKPLUG include ‘usual suspects’ Poison Ivy, Zupdax and 9002.
Злоумышленники также имеют доступ к бэкдору Zupdax: его современные варианты используют аналогичную MyKLoadClient схему исполнения, однако код самого бэкдора берет начало в 2010 году и не может быть однозначно привязан к группе.
Злоумышленники также имеют доступ к бэкдору Zupdax: его современные варианты используют аналогичную MyKLoadClient схему исполнения, однако код самого бэкдора берет начало в 2010 году и не может быть однозначно привязан к группе.
Злоумышленники также имеют доступ к бэкдору Zupdax: его современные варианты используют аналогичную MyKLoadClient схему исполнения, однако код самого бэкдора берет начало в 2010 году и не может быть однозначно привязан к группе.
Злоумышленники также имеют доступ к бэкдору Zupdax: его современные варианты используют аналогичную MyKLoadClient схему исполнения, однако код самого бэкдора берет начало в 2010 году и не может быть однозначно привязан к группе.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Для закрепления на узле группа Space Pirates создает вредоносные сервисы
Группа Space Pirates маскирует свое ВПО под легитимное ПО
ВПО группы Space Pirates шифрует конфигурационные данные и полезную нагрузку с помощью различных алгоритмов
Data transferred is encrypted using RC4 with the encryption key “Microsoft”... Network traffic is LZ-compressed and base64 encoded... usernames and passwords are encrypted and base64 encoded.
ВПО группы Space Pirates поддерживает работу с несколькими C2 и может обновлять список C2 через веб-страницы
Once installed, the main payload connects back to C2 server and sets up communication... It is installed as a service in the Windows System folder, and when run, it sets up communication with C2 server over HTTP.
The malware will in some configurations try to disguise this as legitimate traffic by connecting to port 53 (DNS) on the command & control server, as well as deliberately naming the C2 domains with the ns* (nameserver) prefix.
77 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor using UDT-over-UDP C2 with magic 0x12345678; collects host profiling immediately after connect. Supports plugin-based execution, C2 update, self-removal, and downloading/executing updates. Modern variants use a MyKLoadClient-like dropper/launcher chain (legit siteadv.exe + launcher + encrypted payload ok.obj), often launched via mrun (RC4 + reflective loading). Strong lineage to Redsip (Night Dragon-era) based on identical message structure/magic and command semantics.
Zupdax is cited as another malware family associated with PKPLUG activity, but the content provides no further functional detail.
Malware family referenced as sharing overlapping infrastructure with Farseer.
Модульный бэкдор, существующий как минимум с 2014 года, использующий UDT поверх UDP для связи с C2. Основные возможности сводятся к исполнению дополнительного кода и плагинов, получаемых от управляющего сервера.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.