APTMembers
APT

Fake WebView2 DLL Stalls Sandboxes to Outwait Detection

A Win32 payload disguised as Microsoft's WebView2Loader.dll checks for debuggers, stalls execution, waits for keyboard input, and probes the BIOS before running — buying it enough dwell time to slip past automated sandbox triage. Zenbox flagged it as 'Salat Stealer' at only 52% confidence, but 43 of 76 engines now detect it.

Sep 20, 2026, 14:29 (UTC+9)Last seenSep 20, 2026Severity77ByCTX TeamActorSnowglobeAnimal FarmIOC50RegionsUS

A DLL calling itself WebView2Loader.dll — the file Microsoft's own browser-embedding runtime uses on tens of millions of Windows machines — turns out to be a 3,544KB Win32 payload that checks for an attached debugger, stalls execution for long stretches, waits for a human to actually touch the keyboard, and probes the BIOS before doing anything else.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence