Executive Summary
Security researchers identified a highly specialized, 12 KB Windows backdoor on a single corporate workstation, indicating a likely targeted operation rather than a mass campaign. The malware, which mimics legitimate Realtek audio software, is notable for its unique configuration method: it encodes its command-and-control (C2) domain address as the number of trailing spaces on each line of a fake `desktop.ini` file located in `C:\ProgramData`.
The attack utilized WMI event subscriptions for persistence, triggering the malware at a specific time (19:50) daily to avoid detection during boot. The implant uses a custom C2 protocol involving ICMP echo requests (pings) for initial check-ins before transitioning to HTTP POST requests. Despite its sophisticated concealment, the malware's C2 infrastructure (diagrtrack[.]com) has been inactive since early 2021, leaving the implant in a continuous, unsuccessful polling loop on the infected host.
While no specific threat actor has been named, the custom engineering—including a hand-written entry point without a C runtime and deliberate evasion of string-based scanners—suggests a capable developer. The incident highlights the risks of low-prevalence threats and the necessity of structural detection methods that look beyond standard file content and entropy.
