Tool
UPX
- First Reported
- Apr 29, 2026
- Latest Reported
- Apr 29, 2026
Reported Context (1)
- binaries, infection payloads, proxy credentials, and a target placeholder. The production ARM32 binary was UPX-packed and stripped. The development build wasn't. Cross-referencing both, recovering the ChaCha20 string Operator’s Debug Build Exposes xlabs_v1 DDoS-for-Hire Botnet
Malware (4)
Threat Actors (1)
MITRE ATT&CK (20)
Vendors (5)
Products (2)
Tools (5)
Countries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.