August 16, 2026
- KB-Backdoor — a ~12KB custom Windows backdoor posing as a Realtek audio component was found persisting via a daily WMI scheduled event and hiding its C2 domain inside whitespace characters in a
desktop.inifile. It beaconed over ICMP and HTTP and stayed active long after its C2 domain expired — a deliberately low-profile design that defeats naive static and network detection. @blackorbird · Threat Activity
in Bring Your Own EDR: Turning a Commercial Endpoint Agent Into a Trojan Horse