Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Dyre was a banking Trojan that could spread through an Outlook email chain: a worm used Outlook to send messages with the UPATRE downloader attached to addresses supplied by Dyre’s command server. If a recipient ran the attachment, UPATRE could download a Dyre variant. The email propagation helped distribute the malware, but it did not mean every recipient was infected automatically.

What were Dyre and UPATRE?

Dyre, also known as Dyreza, Dyzap, or Dyranges, was a banking Trojan first observed in 2014. Dell SecureWorks’ Counter Threat Unit said it discovered Dyre in early June 2014. The malware was distributed through the Cutwail spam botnet and later through UPATRE, a downloader that could fetch a Dyre variant.

Dyre’s main purpose was financial theft, not email propagation. It could steal online banking credentials using techniques including man-in-the-browser attacks, which manipulate or observe activity inside a victim’s browser session. The malware also targeted ACH and wire transactions. A backconnect server could let operators interact with a bank website through the infected computer.

How did the Outlook worm spread Dyre?

MyCERT’s 26 March 2015 advisory described a worm that could compose email in Microsoft Outlook. In later versions, the worm used Outlook’s msmapi32.dll mail interface and contact information received from a command-and-control server, according to CCN-CERT’s 29 July 2015 Upatre report summary.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
  1. The worm used Outlook to compose messages and sent them to email addresses supplied by a command server.
  2. It attached the UPATRE downloader to those messages.
  3. If a recipient executed the attachment, UPATRE could download a new Dyre variant.

This was self-propagating in the sense that an infected machine could send more malicious email. The documented chain still required recipients to execute the attachment; the advisories do not establish that simply receiving a message infected the recipient.

How did Dyre first reach computers?

The Outlook worm was one distribution route, not the only one. Dell SecureWorks documented distribution through Cutwail and later through UPATRE. CISA also described a phishing campaign beginning in mid-October 2014 that used changing senders, attachments, exploits, and payloads. One documented route used a weaponized PDF that exploited unpatched Adobe Reader, followed by a Dyre download.

These routes should not be confused with Outlook vulnerabilities. Microsoft’s MS15-131 bulletin said exploitation required a user to open or preview a specially crafted email message in an affected Outlook version. That was a separate vulnerability condition; it does not mean the Dyre worm needed an Outlook flaw to compose and send its messages.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What information did Dyre target?

Dyre sought credentials for online banking and other online services. Its man-in-the-browser techniques could interfere with a banking session, while the backconnect capability gave operators a way to interact with a bank site through the victim’s computer. Dell SecureWorks also described ACH and wire-fraud targeting.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Europol’s 2015 IOCTA assessment said Dyre focused on English-speaking countries and named “over 1000 banks and other organisations.” That is a historical estimate from Europol’s 2015 report, not a current count of targets or evidence that every named organization was compromised.

What should users and organizations take from the incident?

  • Keep Outlook, Office, operating systems, browsers, PDF readers, and endpoint security tools updated. The Dyre campaigns and cited vulnerability bulletins date from 2014–2015; use current vendor guidance for present patch requirements.
  • Apply attachment controls and scrutinize unexpected files, even when a message appears to come from a familiar contact. A compromised computer can send malicious mail through a legitimate mail client.
  • Monitor endpoints for suspicious attachment execution, unexpected Outlook activity, and downloader behavior. Email filtering alone may not stop a chain that uses a victim’s own address book or command-supplied addresses.
  • If a suspicious attachment was executed, treat the computer as potentially compromised: disconnect it from sensitive activity, contact the organization’s security team or a qualified incident responder, and change banking credentials from a known-clean device. Contact the bank promptly if unauthorized transactions may have occurred.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.