FILEMembers
FILE

Fake Windows DLL Targets Singapore Construction Firms in 16-Year Campaign

A 43-kilobyte DLL masquerading as Windows' own language-pack library anchors a two-component implant chain hitting Singapore's construction sector. The toolkit combines DLL search-order hijacking, active sandbox detection, post-execution self-deletion, and service-based persistence — and remains operationally active as of May 2026 despite compile timestamps dated to 2010.

May 28, 2026, 19:00 (UTC+9)Last seenMay 28, 2026Severity62ByCTX TeamActorGoblin PandaCycldekIOC2MITRE23RegionsSG

A 43-kilobyte Windows DLL masquerading as the operating system's own language-pack library is at the centre of an active implant chain targeting Singapore's construction sector — a toolkit that combines DLL search-order hijacking, active sandbox detection, post-execution self-deletion, and service-based persistence into a layered evasion architecture that has remained operationally relevant from its first recorded submission in July 2010 through at least May 2026.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence