C&CMembers
C&C

1-of-76 Dropper Anchors Two-Year Microsoft Path Masquerade Campaign

A freshly compiled Windows executable detected by only one antivirus engine leads a multi-layered implant campaign that has quietly refreshed its toolset for nearly two years. The cluster combines near-invisible droppers, a signed proxyware component, and Cloudflare-fronted C2 domains to sustain long-term espionage access on enterprise Windows hosts.

Jun 3, 2026, 13:58 (UTC+9)Last seenJun 3, 2026Severity100ByCTX TeamActorSpring DragonLotus BlossomIOC16MITRE9

A freshly compiled Windows executable detected by exactly one of 76 antivirus engines sits at the entry point of a multi-layered implant campaign that has been quietly refreshing its toolset for the better part of two years. The file calls itself SecurityHealthServiceSyncUpdate.exe, drops under C:\Program Files\Microsoft\Servicing\, and carries a PE compile timestamp of 2026-05-13 — one day before it first appeared on VirusTotal.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence