FILEMembers
FILE

A Coin-Miner Wearing svchost's Name

A six-indicator bundle tagged to espionage actor APT-C-35 and its 'ehdevel' toolset turns out, on file-by-file review, to contain a decade-old UPX-packed cryptomining dropper disguised as svchost.exe. The rest of the set is inert installer debris and an unconfirmed heuristic hit, leaving the attribution label unsupported by any technical evidence.

Sep 24, 2026, 07:05 (UTC+9)Last seenSep 24, 2026Severity74ByCTX TeamActorAPTC35Donot TeamIOC13MITRE38RegionsPL

A six-indicator bundle arrived tagged to a named espionage actor and a bespoke malware family, but the only file in the set with a confirmed threat classification, matching rule hits, and a sandbox verdict is not an espionage tool at all — it is a UPX-packed cryptomining dropper that renames itself svchost.exe and trips an IDS signature associated with Tor relay traffic.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence