APTMembers
APT

Loader drops two distinct programs disguised as Windows processes

Sandbox records show a loader dropped two executables named for Windows processes and ran both from temporary directories. Their distinct hashes separate the payloads; other records link one to AppData execution and a matching logon launch setting.

Oct 8, 2026, 07:20 (UTC+9)Last seenOct 8, 2026Severity70ByCTX TeamActorAPT27TEMP.HippoIOC10MITRE43RegionsBRCOEGFRIL

A loader placed two executables named svchost.exe and conhost.exe on disk, and sandbox records show both running from a Windows Error Reporting temporary directory. Their familiar names raise a practical question: were these Windows components participating in an application’s execution, or separate programs borrowing Windows identities? The evidence collected by CTX Threat Intelligence supports the second interpretation.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence