APTMembers
APT

Fake 'Jerusalem Brochure' PDF Hides Anti-Debug Spyware Dropper

A Windows dropper disguised as a conference brochure checks for sandboxes and debuggers before contacting a domain registered just weeks earlier. Persistence, WMI-based spreading, and C2 beaconing are all directly evidenced in the sample, while the phishing delivery itself is inferred from matching filenames and timestamps.

Sep 30, 2026, 22:26 (UTC+9)Last seenSep 30, 2026Severity77ByCTX TeamActorAPTC23Two-tailed ScorpionIOC7MITRE36RegionsPS

A Windows dropper built to look like a conference handout — internally named "Brochure-Jerusalem_26082019_pdf.exe" — checks whether anyone is watching it before it does anything else, and only then reaches out to a domain registered ten weeks before the sample was analyzed. The file (284a0c5c…dbd01) carries a matching PDF resource path inside it, reads the CPU clock directly to spot a sandbox, installs itself to survive a reboot, and calls out over WMI to spread to other machines on the same…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence