typetechniquecreated2026-07-31updated2026-07-31defense-evasiondiscoverymalware-familyloader

Mutex Single-Instance Gating

A runtime gating mechanism where malware creates a named mutex (via CreateMutexW) or event (via CreateEventW) on first execution. On subsequent runs, the same call fails with ERROR_ALREADY_EXISTS, and the payload branch is skipped. This prevents redundant execution and can act as a primitive anti-sandbox signal (some sandboxes do not persist named objects between detonations).

Detection / Fingerprint

  • CreateMutexW with a hardcoded or derived name (e.g. Global\<name>, Local\<name>, or plain ASCII string)
  • GetLastError() == ERROR_ALREADY_EXISTS check immediately after
  • Often paired with marker-file-mutex-gating in the same campaign as a fallback mechanism

Observed In

  • phorpiex campaign (sextortion spam bot variants use mutex gating; thin downloader variants use filesystem marker gating instead)

Related Techniques