APTMembers
APT

Downloader Stacks Three Evasion Tricks, Hides C2 in Alibaba DoH Traffic

A trojan tracked as sfuzuan/convagent chains a debugger check, execution stall, and HeavensGate mode switch before resolving command infrastructure through Alibaba's DNS-over-HTTPS service. The technique is far more concretely evidenced than the aging, mostly-dormant domain infrastructure sitting alongside it in the same case.

Sep 16, 2026, 22:43 (UTC+9)Last seenSep 17, 2026Severity100ByCTX TeamActorGold EvergreenBusiness ClubIOC14

A downloader carrying the threat label trojan.sfuzuan/convagent packs three separate anti-analysis tricks into a single unsigned Windows binary — a debugger check, a deliberate stall before execution, and a 32-to-64-bit mode transition known as HeavensGate — and then leans on Alibaba's own DNS-over-HTTPS infrastructure to resolve whatever it talks to next.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence