APTMembers
APT

Windows Defender-Killer Tool Folded Into XRed RAT Dropper

A commodity Defender-disabling hacktool shares its YARA signature with a Synaptics-driver-disguised RAT dropper, showing the defense-evasion code was built directly into the implant rather than dropped separately. The overlap, paired with matching imphashes and dynamic-DNS beaconing, points to a single build pipeline behind the cluster.

Aug 8, 2026, 23:04 (UTC+9)Last seenAug 8, 2026Severity27ByCTX TeamActorGorgon GroupSubaatIOC16MITRE29RegionsHK

A commodity tool built to switch off Windows Defender with one click has turned up inside the build of a remote-access-trojan dropper — not dropped alongside it, but sharing the same crowdsourced YARA signature. The standalone hacktool, tracked publicly as DefenderControl and carried in this set as 1ef6c1a4dfdc39b63bfe650ca81ab89510de6c0d3d7c608ac5be80033e559326, and a Synaptics-driver-themed dropper that sandboxing names as the XRed RAT,…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence