
Layered Windows Trojan Campaign Hits India With Zero-Detection Loader
A disciplined three-toolchain operation targeting India has deployed six unsigned Windows executables and DLLs across three weeks, with its most recent loader stage evading all 76 antivirus engines. The campaign beacons to a Dynu dynamic-DNS node via malformed HTTP requests and rotates infrastructure faster than block lists can track, pointing to an operator actively iterating on payloads rather than running a static toolkit.
Six unsigned Windows executables and DLLs, all carrying copyright strings dated decades into the future, have surfaced across a three-week window targeting India — the product of a disciplined build operation that deploys three structurally distinct payload layers, beacons to a Dynu dynamic-DNS node over deliberately malformed HTTP requests, and has achieved complete evasion of all 76 antivirus engines for its most recently submitted loader stage.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read