C&CMembers
C&C

Fake Speed-Checker Masks a Decade-Long PUP Distribution Platform

A shlayer-family installer masquerading as 'Internet Speed Checker.exe' beacons to a self-signed C2 domain whose TLS certificate openly names itself '*.malware.com'. The backend URL scheme embeds hardcoded affiliate and campaign tokens, revealing a managed distribution-as-a-service platform that has been actively maintained into 2026 despite payload files first seen in 2015.

Jun 3, 2026, 04:26 (UTC+9)Last seenJun 3, 2026Severity100ByCTX TeamIOC19MITRE15

Sixteen HTTPS requests. Two path templates. One hardcoded affiliate token. The architecture behind a shlayer-family PUP operation targeting energy-sector endpoints turns out to be less a piece of malware and more a managed distribution platform — one whose C2 infrastructure has been actively maintained into 2026 despite payload files that first appeared on VirusTotal in the summer of 2015.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence