Mutex Single-Instance Gating
A runtime gating mechanism where malware creates a named mutex (via CreateMutexW) or event (via CreateEventW) on first execution. On subsequent runs, the same call fails with ERROR_ALREADY_EXISTS, and the payload branch is skipped. This prevents redundant execution and can act as a primitive anti-sandbox signal (some sandboxes do not persist named objects between detonations).
Detection / Fingerprint
CreateMutexWwith a hardcoded or derived name (e.g.Global\<name>,Local\<name>, or plain ASCII string)GetLastError() == ERROR_ALREADY_EXISTScheck immediately after- Often paired with
marker-file-mutex-gatingin the same campaign as a fallback mechanism
Observed In
- phorpiex campaign (sextortion spam bot variants use mutex gating; thin downloader variants use filesystem marker gating instead)
Related Techniques
- marker-file-mutex-gating — filesystem-based alternative when named mutexes are too noisy