← Back to Feed
A 12 KB Backdoor Hid Its C2 Domain in desktop.ini Whitespace
August 14, 2026 · Gen Digital · Severity: MEDIUM
A hand-crafted Windows backdoor, only 12 KB in size, concealed its command-and-control domain as the number of trailing spaces in a fake desktop.ini file. The malware was found on exactly one machine, highlighting a highly targeted operation that relied on steganographic hiding to evade detection.
Key Takeaways
- A 12 KB Windows backdoor hid its C2 domain using trailing spaces in a desktop.ini file.
- The stealthy technique was discovered on a single machine, indicating a narrowly targeted attack.
- Manual analysis was required to extract the hidden command-and-control domain from whitespace.