2026-07-08NOTABLEUnit 42: Factory-v3 loaders use fake Authenticode signing and 491 MB file inflation to evade sandboxes
Factory-v3
tool · tool:factory-v3-loader-builder single-source
Malware-as-a-service Go loader-builder documented by Palo Alto Unit 42 (2026-07-07) delivering Vidar stealer and XMRig via fraudulent Authenticode code-signing, fake MpClient.dll DLL-sideloading against Defender, in-memory AMSI patching and 'file inflation' (null-padding to ~491 MB) sandbox evasion; operator tracked via a Telegram channel branded 'X3D MINER'.
Coverage
1
first 2026-07-08 → last 2026-07-08
Latest activity
2026-07-08
Unit 42: Factory-v3 loaders use fake Authenticode signing and 491 MB file inflation to evade sandboxes
Peak priority
notable
1 notable
Targets
technology
sectors: technology · regions: us, europe
Sources cited
1
1 hosts
Action items (2)
Do-now tasks recorded on the entries about Factory-v3, newest first. Check the date before acting on an older one.
- Tune sandbox/EDR heuristics for PE file-inflation (section-table size vs. file-size mismatch; anomalously large files) so 491 MB null-padded loaders are not silently skipped past detonation size limits.2026-07-08Unit 42: Factory-v3 loaders use fake Authenticode…
- Flag Authenticode signer/product mismatches (e.g. binaries signed as JustWatch GmbH or BleacherReport that are not those products) and MpClient.dll load-path anomalies / NisSrv.exe running from %AppData%.2026-07-08Unit 42: Factory-v3 loaders use fake Authenticode…
Defender insights
What each entry about Factory-v3 tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (3 across 3 tactics)
3 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ExecutionHijack Execution Flow: DLL
- StealthHijack Execution Flow: DLL
- Defense ImpairmentSubvert Trust Controls: Code Signing · Disable or Modify Tools
Execution TA0002
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-07-08/unit42-factory-v3-loader-vidar-xmrig-sandbox-evasion · ATT&CK page ↗
Stealth TA0005
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-07-08/unit42-factory-v3-loader-vidar-xmrig-sandbox-evasion · ATT&CK page ↗
Defense Impairment TA0112
T1553.002Subvert Trust Controls: Code Signing×1
Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. The certificates used during an operation may be created, acquired, or stolen by the adversary. Unlike Invalid Code Signature, this activity will result in a valid signature.
Evidence: 2026-07-08/unit42-factory-v3-loader-vidar-xmrig-sandbox-evasion · ATT&CK page ↗
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-07-08/unit42-factory-v3-loader-vidar-xmrig-sandbox-evasion · ATT&CK page ↗
Entries about Factory-v3 (1)
Where this entity is cited
Source distribution
- unit42.paloaltonetworks.com1 (100%)