← Back to Feed

A 12 KB Backdoor Hid Its C2 Domain in desktop.ini Whitespace

August 14, 2026 · Gen Digital · Severity: MEDIUM

A hand-crafted Windows backdoor, only 12 KB in size, concealed its command-and-control domain as the number of trailing spaces in a fake desktop.ini file. The malware was found on exactly one machine, highlighting a highly targeted operation that relied on steganographic hiding to evade detection.

Key Takeaways

  • A 12 KB Windows backdoor hid its C2 domain using trailing spaces in a desktop.ini file.
  • The stealthy technique was discovered on a single machine, indicating a narrowly targeted attack.
  • Manual analysis was required to extract the hidden command-and-control domain from whitespace.
☕ Buy a Coffee