FILEMembers
FILE

5KB Fake 'update.exe' Stager Ties to Tomiris/YoroTrooper Espionage

A five-kilobyte unsigned .NET binary disguised as a Windows update file was served directly from a bare IP address rather than a spoofed domain, trading stealth for speed. Detection engines link it to the espionage-focused Tomiris and YoroTrooper clusters despite an AgentTesla commodity-stealer label.

Sep 22, 2026, 14:47 (UTC+9)Last seenSep 22, 2026Severity62ByCTX TeamActorTomirisYoroTrooperIOC3MITRE12RegionsCHJOUS

A stager built to pass as nothing more than a routine Windows update file is barely large enough to hold its own icon — five kilobytes of packed .NET code, unsigned, dropped straight into C:\Windows\Temp\update.exe. Despite the size, 55 of 76 antivirus engines flag it, and the record ties the sample (4f237b5a…) to the espionage-focused Tomiris and YoroTrooper clusters.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence