A WhatsApp message disguised as a finance report is being used to infect Windows computers in Malaysia with a malware loader that hides behind a valid code-signing certificate issued to Guangzhou Kugou Technology, according to research published on 27 September 2026 by Pelagos Intel.
The infection ends with the compromised PC repeatedly calling a command-and-control (C2) server at 134.122.155.135 on port 443, and Pelagos says the techniques resemble those of the Silver Fox threat group.
The attachment, named PDF_C2841_20260911100446.zip, arrives with a message asking the recipient to forward the report for verification and to open it on a computer. That second instruction moves the victim off the phone and onto Windows, where the payload can run. Inside the ZIP is an IMG disk image, a file type that Windows mounts and opens like a removable drive.
The disk image carries two files. The first is an executable that presents itself as KuGou software and carries a genuine Authenticode signature from Guangzhou Kugou Technology Co., Ltd., which Windows reports as valid. The second is an unsigned DLL, active_desktop_render_x64.dll, whose metadata claims to be a Microsoft Desktop Window Manager helper with the original filename dwmapi.dll.

The pairing is a classic sideloading setup, in which a trusted program loads a malicious library placed next to it. Pelagos found that the signed launcher calls two functions exported by the DLL, SetDesktopMonitorHook and ClearDesktopMonitorHook. The DLL then looks up Windows functions through hashed identifiers, decodes hidden data with XOR, and writes a transformed 11,200-byte block into executable memory. The same signature check Windows uses to tell users a file can be trusted is what vouches for the launcher that starts the chain.
Dynamic analysis tied the pieces together. A Windows decryption call produced an output of exactly 11,200 bytes, and the decrypted data held a configuration marker, @@RAPID_CFG_START@@, the C2 address, port 443, and a Chinese label meaning “Default group”. The malware copied both files to %APPDATA%\Microsoft\Update, added a Registry Run value named MicrosoftUpdate so it restarts at every login, and makes 96 connection attempts to the server at roughly three-second intervals. The ZIP delivered over WhatsApp carries the number C2841, while the executable Pelagos analysed is numbered C2089. The report does not explain the difference.
Silver Fox links stop short of a match

Pelagos compares the chain to a Silver Fox campaign against India documented by CloudSEK in December 2025. That campaign delivered the ValleyRAT remote access trojan by pairing a legitimately signed Thunder.exe from Xunlei with a malicious libexpat.dll. Both operations use signed software to launch a rogue DLL, in-memory execution, configurable C2 settings, and persistent retry behaviour. Pelagos says the similarity holds at the tradecraft level and is “not an exact campaign match”. The report does not name the final payload.
Malaysia has been the main target of WhatsApp-borne Windows malware this year. In June 2026, Kaspersky reported a campaign that used compromised WhatsApp accounts to send VBScript files posing as business documents. Eighty per cent of its victims were in Malaysia, and its infrastructure overlapped with earlier ValleyRAT and Gh0st RAT activity.
Kaspersky urged caution with “unexpected attachments through WhatsApp, even when they appear to originate from known contacts”. No link between that campaign and the one Pelagos analysed has been established.
Users of WhatsApp Desktop or WhatsApp Web on Windows should not open ZIP or IMG files that arrive as “PDF” reports, regardless of who sends them. An MicrosoftUpdate entry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run pointing to %APPDATA%\Microsoft\Update is a strong sign of infection. During the June campaign, Malaysia’s Computer Emergency Response Team (MyCERT) advised infected users to disconnect the machine from the internet, change passwords from a separate clean device, and report the incident to Cyber999.
Several questions remain open. Pelagos has not said how many people received the lure or whether it was sent from hijacked accounts. It has also not said whether the KuGou certificate, thumbprint 757BDD02CBA91CA59C46E2098A5479C1ABC1FDBE, was stolen or misused, or whether KuGou or the issuing certificate authority has been notified. The report lists file hashes for the ZIP, IMG, EXE, and DLL for defenders who want to hunt for the samples.
Community Discussion
Join the conversation. Ask questions, share solutions, and help others.
Be the first to start the discussion!
