
FILEMembers
FILEFake Windows Update Binary Hides Stealc Credential Stealer
A file named wsus.exe poses as a Windows Update helper while carrying anti-analysis stalling code and a payload that a specific YARA rule ties to the Stealc stealer family. Most antivirus engines flag it only under generic trojan names, masking the actual threat underneath.
Sep 10, 2026, 14:52 (UTC+9)Last seenSep 10, 2026Severity62ByCTX TeamActorSilenceContract CrewIOC5MITRE23RegionsCHCNJO
A binary that calls itself wsus.exe, complete with a spoofed "AdobeReaderFlash Corporation" copyright string, has been circulating disguised as a routine Windows Update helper — and underneath the generic trojan labels most antivirus engines assign it, a named detection rule identifies the payload specifically as Stealc, a known credential-stealing family.
Members only
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to readSource: CTX Threat Intelligence