APTMembers
APT

Installer Hides Its Only Flagged File Among Ten Clean Decoys

Ten PNG and CSS files from a generic setup wizard register zero detections, while a single packed, unsigned executable bundled alongside them trips eighteen antivirus engines. The split shows a trojanized installer where the scannable surface and the actual payload never overlap.

Sep 11, 2026, 23:46 (UTC+9)Last seenSep 12, 2026Severity17ByCTX TeamActorSnowglobeAnimal FarmIOC20MITRE27RegionsUS

Ten PNG and CSS files with an identical creation moment sit alongside a single packed Windows executable that carries every detection in the set — a pairing that reads less like a malware family and more like the internals of an ordinary software installer, repurposed. The image assets are unremarkable on inspection: a close button, a hover state, a grey button, a progress bar, a stylesheet named main.css. Individually they register 0/53 to 0/57 across antivirus engines.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence