APTMembers
APT

Packed svchost.exe Dropper Reveals Tor C2 Inside Sparse APT Feed

A UPX-packed binary posing as svchost.exe is the only richly-documented artifact among 58 file hashes tied to a Donot Team/APT-C-35 indicator set. It shows a full chain from masquerading and anti-debug packing through WMI discovery to Tor-routed command-and-control, while 56 other hashes carry no usable telemetry.

Jul 9, 2026, 18:41 (UTC+9)Last seenJul 9, 2026Severity72ByCTX TeamActorAPTC35Donot TeamIOC62RegionsPL

A single UPX-packed binary sitting inside an otherwise thin indicator set shows a strikingly complete tradecraft arc — from disguised execution through anti-analysis packing to discovery and an anonymized command channel — even though the wider record around it barely holds together. The sample, a 7-megabyte Win32 executable that VirusTotal engines label trojan.dekimine, installs itself as %APPDATA%\pwo6\svchost.exe, borrowing the name of a core Windows process while stashing alternate copies…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence