APTMembers
APT

Cobalt Strike Loader Masks as Crash-Reporter, Hides Behind Default TLS Cert

A December 2024 ZIP archive built in a four-minute window bundles a Cobalt Strike loader disguised as BugSplat and print-spooler DLLs, engineered to stall sandboxes and wait for human interaction before beaconing to an Argentina-hosted IP running an unmodified OpenSSL demo certificate.

Jun 26, 2026, 09:21 (UTC+9)Last seenAug 26, 2026Severity100ByCTX TeamActorBariumWicked SpiderIOC7MITRE32RegionsCH

A loader package built inside a single four-minute window in December 2024 bundles a Windows executable and two DLLs designed to look like ordinary Windows utility software — one impersonating a game-crash reporting library, the other borrowing the name of a print-spooler helper. Once unpacked, the components stall, check for a debugger, and wait for a human to interact with the machine before doing anything else, a staging sequence built specifically to survive automated malware sandboxes.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence