UPPERCUT

S0275

Malware.View on attack.mitre.org

About this malware

UPPERCUT is a 32-bit HTTP-based backdoor that has been used by menuPass since at least 2017. Once thought to be exclusive to menuPass, UPPERCUT was also observed being used by menuPass-associated MirrorFace during Operation AkaiRyū.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1005
Data from Local System

UPPERCUT can upload files to the C2 from infected machines.

T1016
System Network Configuration Discovery

UPPERCUT has the capability to gather the victim's proxy information.

T1033
System Owner/User Discovery

UPPERCUT has the capability to collect the current logged on user’s username from a machine.

T1059.003
Windows Command Shell

UPPERCUT uses cmd.exe to execute commands on the victim’s machine.

T1071.001
Web Protocols

UPPERCUT has used HTTP for C2, including sending error codes in cookie headers.

T1082
System Information Discovery

UPPERCUT has the capability to gather the system’s hostname and OS version.

T1083
File and Directory Discovery

UPPERCUT has the capability to gather the victim's current directory.

T1105
Ingress Tool Transfer

UPPERCUT can download and upload files to and from the victim’s machine.

T1113
Screen Capture

UPPERCUT can capture desktop screenshots in the PNG format and send them to the C2 server.

T1124
System Time Discovery

UPPERCUT has the capability to obtain the time zone information and the current timestamp of the victim’s machine.

T1132.001
Standard Encoding

UPPERCUT can base64 encode C2 communications.

T1548.002
Bypass User Account Control

UPPERCUT contains functionality to bypass UAC.

T1573.001
Symmetric Cryptography

Some versions of UPPERCUT have used the hard-coded string “this is the encrypt key” for Blowfish encryption when communicating with a C2. Later versions have hard-coded keys uniquely for each C2 address. UPPERCUT has also used custom ChaCha20, XOR, and LZO algorithms for C2 communication.

T1574.001
DLL

UPPERCUT has been sideloaded through a legitimately signed application from the JustSystems Corporation.

T1678
Delay Execution

UPPERCUT can use a sleep function to delay execution.

Groups that use it2

Campaigns1

References2

  1. FireEye APT10 Sept 2018 Open source
    Matsuda, A., Muhammad I. (2018, September 13). APT10 Targeting Japanese Corporations Using Updated TTPs. Retrieved September 17, 2018.
  2. Trend Micro Earth Kasha Anel NOV 2024 Open source
    Hiroaki, H. (2024, November 26). Guess Who’s Back - The Return of ANEL in the Recent Earth Kasha Spear-phishing Campaign in 2024. Retrieved April 17, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.