
Fake 'Intel Driver' Malware Checks for Sandboxes Before Striking
An unsigned binary called Inteldriver.exe leads a 24-hash batch labeled APT28 with 85% confidence, but only this one file carries usable telemetry. It shows deliberate anti-debugging checks and a DonutLoader-style shellcode stage hidden in a high-entropy resource section.
Before it does anything else, the binary looks around. A Win32 executable calling itself Inteldriver.exe — a name chosen to blend into a driver folder or a running-process list rather than draw attention — spends its opening moves probing the machine it has landed on for signs of a sandbox or a debugger. That single behavioural signal, carried by a file that VirusTotal shows 39 of 75 engines flagging as malicious, is the most concrete piece of tradecraft in an otherwise thin batch of 24 file…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read