
Fake Windows DLL Targets Singapore Construction Firms in 16-Year Campaign
A 43-kilobyte DLL masquerading as Windows' own language-pack library anchors a two-component implant chain hitting Singapore's construction sector. The toolkit combines DLL search-order hijacking, active sandbox detection, post-execution self-deletion, and service-based persistence — and remains operationally active as of May 2026 despite compile timestamps dated to 2010.
A 43-kilobyte Windows DLL masquerading as the operating system's own language-pack library is at the centre of an active implant chain targeting Singapore's construction sector — a toolkit that combines DLL search-order hijacking, active sandbox detection, post-execution self-deletion, and service-based persistence into a layered evasion architecture that has remained operationally relevant from its first recorded submission in July 2010 through at least May 2026.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read