C&CMembers
C&C

PANMAP Dropper Fakes Microsoft Branding, C2 Cert Predates Domain

A Win32 dropper called PANMAP borrows Microsoft's product name and copyright text yet carries no valid code signature at all, staging additional modules via appended data rather than a signed payload. It connects to a single C2 domain whose self-signed certificate expired eleven days before the domain itself was even registered.

Sep 1, 2026, 22:41 (UTC+9)Last seenSep 1, 2026Severity100ByCTX TeamActorSmoky SpiderIOC3MITRE21RegionsCHJO

A Win32 dropper carrying the internal name PANMAP and presenting itself as PANMAP.DLL — complete with a product string reading "Microsoft® Windows® Operating System" and a Microsoft copyright line — ships with no valid code signature at all; signature validation on the binary fails outright. That single contradiction, a file dressed head-to-toe in Microsoft branding while carrying zero cryptographic proof of Microsoft origin, is the cleanest piece of tradecraft in this record, and it anchors a…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence