logo

Hackers Abuse Microsoft Fondue.exe to Side-Load APPWIZ.cpl and Execute Malware

ID: 01edecea-00ff-593a-ad01-1ff1b8566cd6

STIX ID: report--01edecea-00ff-593a-ad01-1ff1b8566cd6

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Tushar Subhra Dutta

...
...

A targeted campaign abuses the Windows Features on Demand UX binary (Fondue.exe) to side-load a malicious APPWIZ.cpl that launches a Sliver post-exploitation implant and a separate SoullessRAT; attackers distribute malicious MSI installers disguised as developer and drone-related apps, establish persistence via a stealthy scheduled task, and communicate with identified C2 domains. The report provides IoCs (SHA256 hashes, domains, URLs, filenames, mutex, scheduled task, staging directory) and detection recommendations such as monitoring non-standard Fondue.exe execution, CPL/DLL side-loading, and suspicious scheduled tasks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.