CPlApplet PNG Payload Dropper
Phorpiex variant that abuses the CPlApplet export interface (typically used by Control Panel applets) to masquerade as a benign system component while decrypting a companion payload.png file. Observed in sample 45d0464a (May 2026).
Pattern
- Carrier PE exports
CPlAppletto appear as a legitimate Control Panel applet. - At runtime, expects a
payload.pngfile in the same directory (or a hardcoded path). - Decrypts/decompresses the PNG payload into a second-stage DLL.
- Self-erases the carrier and executes the DLL.
Detection
- PE with
CPlAppletexport but no legitimate CPL metadata. - Companion
payload.pngwith high entropy or non-standard headers. pngsteganography tools (e.g.,zsteg,steghide) reveal embedded PE headers.
Observed In
- phorpiex sample
45d0464a(May 2026 build, x64, dynamic API hashing, self-erasure).