Sophos X-Ops reported a malicious Windows backdoor that was discovered after a false-positive review of an executable signed with a valid Microsoft Windows Hardware Compatibility Publisher certificate. The malware appeared to impersonate Thales, installed itself as a service named CatalogWatcher, embedded the 3proxy proxy server, and used an XOR-obfuscated command-and-control domain, catalog[.]micrisoftdrivers[.]com. Sophos said the abuse was serious because the trusted signature could help the malware evade scrutiny and blend into enterprise environments.
Telemetry and VirusTotal data linked the backdoor to the LaiXi Android Screen Mirroring product, with related samples dating back to at least January 2023 across four compilation clusters that included signed and unsigned variants. Sophos said it found no evidence that LaiXi’s developers intentionally shipped the malware or that a broader supply-chain compromise had occurred, but urged caution because the association persisted over time. Microsoft was notified through the Microsoft Security Response Center and later added the affected files to its revocation list under CVE-2024-26234.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
In December 2023, Sophos X-Ops analyzed a malicious backdoor after a false positive report involving an executable signed with a valid Microsoft Windows Hardware Compatibility Publisher certificate. The malware installed itself as a service named CatalogWatcher and embedded the 3proxy proxy server.
Microsoft later added the relevant files to its revocation list as part of Patch Tuesday under CVE-2024-26234. This action followed Sophos's report about the signed backdoor.
After analyzing the malware, Sophos reported the abuse of the Microsoft Windows Hardware Compatibility Publisher certificate to the Microsoft Security Response Center. The backdoor used an XOR-obfuscated command-and-control domain, catalog[.]micrisoftdrivers[.]com.
Threat hunting identified related malware variants across multiple compilation clusters, with the linkage between the LaiXi Android Screen Mirroring product and the backdoor dating back to at least January 2023. Sophos said it found signed, unsigned, and differently signed samples from January through October 2023.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.