APTMembers
APT

Emotet OCX Loader Beacons to Four Continents via regsvr32 Proxy

A 64-bit DLL disguised as an OLE Control Extension file uses regsvr32 to proxy its execution and contacts four geographically dispersed C2 servers spanning Malaysia, Ghana, Germany, and South Korea. The payload's high-entropy resource section, zero-import table, and Dridex-overlapping TLS fingerprint point to an active Emotet deployment with potential banking trojan second-stage delivery still observable as recently as June 2026.

Jun 12, 2026, 06:42 (UTC+9)Last seenJun 12, 2026Severity100ByCTX TeamActorEmotet GroupTA542IOC12MITRE21RegionsGEQA

A 64-bit Windows DLL masquerading as an OLE Control Extension file — delivered under the name hvxda.ocx and designed to run through regsvr32 rather than a conventional executable launcher — sits at the centre of an active Emotet deployment that has been beaconing to four geographically dispersed command-and-control servers across Malaysia, Ghana, Germany, and South Korea.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence