FILEMembers
FILE

Fake 'Intel Driver' Malware Checks for Sandboxes Before Striking

An unsigned binary called Inteldriver.exe leads a 24-hash batch labeled APT28 with 85% confidence, but only this one file carries usable telemetry. It shows deliberate anti-debugging checks and a DonutLoader-style shellcode stage hidden in a high-entropy resource section.

Jul 25, 2026, 05:49 (UTC+9)Last seenJul 25, 2026Severity52ByCTX TeamActorAPT28StrontiumIOC26MITRE13RegionsCAES

Before it does anything else, the binary looks around. A Win32 executable calling itself Inteldriver.exe — a name chosen to blend into a driver folder or a running-process list rather than draw attention — spends its opening moves probing the machine it has landed on for signs of a sandbox or a debugger. That single behavioural signal, carried by a file that VirusTotal shows 39 of 75 engines flagging as malicious, is the most concrete piece of tradecraft in an otherwise thin batch of 24 file…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence