In mid-January 2026, security team detected unusual activity in a corporate environment that, at first, did not seem alarming. The signs were subtle and did not trigger alerts from standard endpoint protection tools such as antivirus software.
The event appeared insignificant until deeper investigation revealed it to be a sophisticated, multi-stage cyberattack. This kind of low-profile, high-impact intrusion carries significant risk for organizations that rely on data integrity and trust.
The Attack Unfolds
CyStack’s investigation focused on a single workstation within the customer support team. The chain of events began when a support staff member clicked on a link in a Zendesk ticket, which led to the download and execution of a suspicious .pif file.
Although the file appeared harmless at first glance, it was actually an executable file disguised with a .pif extension, which is often overlooked in modern systems where file extensions are hidden by default.
.webp)
The downloaded file, referred to as the Dropper, initiated a series of operations that allowed attackers to install and run additional malicious payloads on the system.
The file was digitally signed at the time of distribution, adding a layer of legitimacy that helped it bypass standard security checks such as reputation-based scanners and SmartScreen filters.
Further analysis revealed the attack involved several stages:
- File System Residues – Traces left in system logs and files pointed to a staged attack that used techniques such as DLL sideloading and obfuscated executables that ran in memory to avoid detection.
- Registry Entries and Service Configuration – Key registry entries and Windows service configurations were altered to ensure persistence across system reboots.
- In-Memory Payload Execution – The final payload was executed entirely in memory, reducing the chances of detection by file-based defenses.
Despite the stealthiness of the attack, it was clear that the perpetrators sought to avoid raising any alarms by blending the malicious activities with normal system processes.
There was no evidence that the malware spread laterally to other systems. However, the attack’s design suggests the threat actor could easily expand the compromise if left undetected.

Signs Point To APT-Q-27
According to Cystack, the attack was traced back to a command-and-control (C&C) infrastructure with several indicators that closely matched known activity linked to the APT-Q-27 group, also known as GoldenEyeDog.
Although it couldn’t be definitively attributed to APT-Q-27, the similarities were striking enough to raise concerns.
Key indicators included the naming conventions within the C2 infrastructure, the modular design of the backdoor, and the multi-stage architecture, a hallmark of earlier APT-Q-27 campaigns.
Notably, the C&C servers were distributed across several regions, including Hong Kong, Japan, and the United States, consistent with the geographic distribution often observed in advanced persistent threat (APT) operations.
The attackers used a file named updat.log, a container designed to carry encrypted payloads, similar to those found in past APT-Q-27 campaigns.

Additionally, the attackers employed a plugin-based backdoor architecture, enabling them to activate or deactivate various attack capabilities on needed.
| IOC Category | Details |
|---|---|
| C2 Domains/IPs | wk.goldeyeuu.io (Tokyo), 1.32.250.21 (HK), 103.145.87.3 (HK), 192.252.182.53 (CA, US), 27.124.41.140 (HK), 103.151.44.6 (India) |
| MD5 Hashes | 64B07B1C385CF94A3559E323009F7641 (updat.exe), 30917B5ABB991DF495827A9D7C7EBCBC (crashreport.dll), 543023ACE4F10B736C4C4109E005F0EF (updat.log), B591EE37860F35A788B10531A00BBBD2 |
| URLs | hxxps://yyupdats[.]s3.ap-southeast-1.amazonaws.com/{updat.txt/exe/dll/log}, hxxps://yy-service[.]s3.ap-northeast-2.amazonaws.com/{yy.txt/exe/dll/log} |
| MITRE | T1566.002 (phishing), T1553.002 (signing), T1620 (reflective), T1543.003 (service), T1548.002 (UAC), T1070 (cleanup) |
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.