APTMembers
APT

Fake Synaptics Driver Rebuilt for Three Years, Now a Confirmed RAT

One unsigned Win32 loader — same imphash, same forged 1992 timestamp, same fake driver identity — has been recompiled from December 2020 through November 2023. It aged from a static DarkKomet trojan label into a sandbox-confirmed XRed/XWorm remote-access tool without ever changing its builder chassis.

Jun 7, 2026, 07:20 (UTC+9)Last seenJul 2, 2026Severity100ByCTX TeamActorIndraPredatory SparrowIOC18RegionsEC

Three unsigned Win32 loaders — the oldest first appearing in December 2020, the newest surfacing in November 2023 — share one imphash, an identical PE section layout down to the byte, and a forged compile timestamp of 1992-06-19 that predates Windows 95. All three carry the same fake product string, "Synaptics Pointing Device Driver," version 1.0.0.4, and two of them drop to the identical path, C:\ProgramData\Synaptics\Synaptics.exe.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence