
Fake WebView2 DLL Stalls Sandboxes to Outwait Detection
A Win32 payload disguised as Microsoft's WebView2Loader.dll checks for debuggers, stalls execution, waits for keyboard input, and probes the BIOS before running — buying it enough dwell time to slip past automated sandbox triage. Zenbox flagged it as 'Salat Stealer' at only 52% confidence, but 43 of 76 engines now detect it.
A DLL calling itself WebView2Loader.dll — the file Microsoft's own browser-embedding runtime uses on tens of millions of Windows machines — turns out to be a 3,544KB Win32 payload that checks for an attached debugger, stalls execution for long stretches, waits for a human to actually touch the keyboard, and probes the BIOS before doing anything else.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read