Since the beginning of the year, the United States has been the country with the most reported problems with the downloader malware, with a number exceeding 5,000,000.
Upatre is used as a means of distributing other malicious software with capabilities such as sending spam messages and disabling specific processes running on a computer in order to intercept sensitive information.
The preference shown by hackers for the US is well known and from the map with the countries where the Upatre downloader has been distributed, it seems that their targeting of the country is significantly greater than all other parts of the world. According to data from the Microsoft Malware Protection Center (MMPC), the second country where Upatre appears is Ireland with 789,970 registrations, almost seven times less than the US.
Incident records for the remaining countries are less than 100,000, with Canada taking third place with 97,608. This is followed by the United Kingdom (75,550), Australia (26,156), France (19,098), Spain (16,335), Mexico (15,734) and Japan (15,176).
Upatre is distributed to computers via emails carrying the downloader, originating from botnets such as Hesdenand Cutwail. Once the computer is infected, Upatre connects to a C&C server to receive instructions on the malware to download to the system.
Patrick Estavillo, a software engineer at Microsoft, says that the downloader typically installs the Hesden and Cutwail packages to accelerate the spread of the malware via spam emails, a typical method for such scams. This is also the reason for the high number of detections in just two months.

