
Fake Synaptics Driver Rebuilt for Three Years, Now a Confirmed RAT
One unsigned Win32 loader — same imphash, same forged 1992 timestamp, same fake driver identity — has been recompiled from December 2020 through November 2023. It aged from a static DarkKomet trojan label into a sandbox-confirmed XRed/XWorm remote-access tool without ever changing its builder chassis.
Three unsigned Win32 loaders — the oldest first appearing in December 2020, the newest surfacing in November 2023 — share one imphash, an identical PE section layout down to the byte, and a forged compile timestamp of 1992-06-19 that predates Windows 95. All three carry the same fake product string, "Synaptics Pointing Device Driver," version 1.0.0.4, and two of them drop to the identical path, C:\ProgramData\Synaptics\Synaptics.exe.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read