
Fake Speed-Checker Masks a Decade-Long PUP Distribution Platform
A shlayer-family installer masquerading as 'Internet Speed Checker.exe' beacons to a self-signed C2 domain whose TLS certificate openly names itself '*.malware.com'. The backend URL scheme embeds hardcoded affiliate and campaign tokens, revealing a managed distribution-as-a-service platform that has been actively maintained into 2026 despite payload files first seen in 2015.
Sixteen HTTPS requests. Two path templates. One hardcoded affiliate token. The architecture behind a shlayer-family PUP operation targeting energy-sector endpoints turns out to be less a piece of malware and more a managed distribution platform — one whose C2 infrastructure has been actively maintained into 2026 despite payload files that first appeared on VirusTotal in the summer of 2015.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read