logo

Along for the ride: When legitimate software becomes a signed malware loader

ID: d5242437-a708-520b-8f57-50fa7b72c73a

STIX ID: report--d5242437-a708-520b-8f57-50fa7b72c73a

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2025-10-23

Date Updated: 2026-04-27

Author: Marcus Hutchins

...
...

This technical blog analyzes a second-stage malicious loader that trojanizes the legitimate Greenshot screenshot tool (renamed FortiClientCompliance.exe) by replacing GreenshotPlugin.dll with a malicious version that displays a fake FortiClient compliance UI, loads a native updater.dll which creates a scheduled task for persistence, decrypts shellcode from an embedded icon, and executes it in-memory; the malware employs advanced evasion (indirect syscalls to evade user-mode hooks) and masks C2 communications as benign jQuery requests with encrypted data in a Cloudflare cookie. IOCs and file hashes are provided, the C2 was observed alive during analysis, but no follow-up payload was retrieved and attribution remains unclear.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.