typetechniqueconfidencemediumcreated2026-09-01updated2026-09-01phorpiexdropperpayload-stagingmasqueradecplapplet

CPlApplet PNG Payload Dropper

Phorpiex variant that abuses the CPlApplet export interface (typically used by Control Panel applets) to masquerade as a benign system component while decrypting a companion payload.png file. Observed in sample 45d0464a (May 2026).

Pattern

  • Carrier PE exports CPlApplet to appear as a legitimate Control Panel applet.
  • At runtime, expects a payload.png file in the same directory (or a hardcoded path).
  • Decrypts/decompresses the PNG payload into a second-stage DLL.
  • Self-erases the carrier and executes the DLL.

Detection

  • PE with CPlApplet export but no legitimate CPL metadata.
  • Companion payload.png with high entropy or non-standard headers.
  • png steganography tools (e.g., zsteg, steghide) reveal embedded PE headers.

Observed In

  • phorpiex sample 45d0464a (May 2026 build, x64, dynamic API hashing, self-erasure).

References