FILEMembers
FILE

Thailand Telco Trojan Hides Banking Payload Inside Fake IDM Crack

A trojanised Internet Download Manager crack seeded across piracy channels is delivering a banking-capable payload to Thailand's telecommunications sector. The campaign pairs a UPX-packed 59 KB stub with a 12 MB multi-stage dropper that evades automated sandboxes, executes via WMI, and phones home to a ten-day-old C2 domain no reputation feed has yet flagged.

Jun 14, 2026, 03:28 (UTC+9)Last seenJun 14, 2026Severity100ByCTX TeamIOC22MITRE47RegionsTH

Somewhere between a piracy forum and a Thai telecom workstation, a 59-kilobyte executable named IDM_6.4x_Crack_v19.7.exe is doing something its would-be users never expected: running a layered evasion gauntlet that defeats at least one automated sandbox entirely before handing off to a 12-megabyte dropper that quietly installs a banking-capable payload, establishes registry persistence, and then erases itself from disk.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence