APTMembers
APT

One Static Token Ties Four Rotating DarkHotel C2 Domains Together

An unsigned, Adobe-disguised downloader (Catch.exe/update.exe) carries virtualization, sandbox, and debugger evasion before beaconing to four separate dynamic-DNS domains — all hitting the identical /bin/home/home.php path with the same static parameter, revealing one reused C2 backend behind disposable fronts.

Aug 23, 2026, 14:27 (UTC+9)Last seenAug 23, 2026Severity100ByCTX TeamActorDarkHotelFallout TeamIOC21MITRE10RegionsJP

An unsigned 2.4MB Windows executable masquerading as an Adobe updater (catalogued as 672c82c1…d26b65ef, and referred to here as the Catch.exe downloader after its internal name) carries a full anti-analysis stack — virtualization and sandbox checks [T1497, T1497.002, T1497.003], debugger evasion [T1622], and code injection into another process's window memory [T1055.011] — before it ever reaches out to command infrastructure.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence