A technical walkthrough demonstrated how Windows executables can be modified to display convincing version information and familiar application icons without changing their trustworthiness or adding a valid publisher signature. Using a simple C program, a resource script, and the MinGW-w64 toolchain, the author showed how VERSIONINFO fields such as CompanyName, FileDescription, FileVersion, OriginalFilename, and ProductName, along with ICON resources, can be compiled into the .rsrc section of a PE file and linked into a final executable.
The examples included a benign message-box program first built without resources and then rebuilt with custom metadata and a browser-style icon to illustrate how attackers can impersonate legitimate software branding while remaining unsigned and untrusted. The reporting stressed that these fields are self-declared cosmetic indicators rather than proof of legitimacy, and that defenders should validate Windows binaries with stronger signals such as Authenticode status, file location, behavior, imports, and overall provenance instead of trusting icons or version strings alone.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
The walkthrough presented a second executable, hack2.exe, built with a browser-style icon embedded through a separate resource script. The article said the sample was uploaded to ANY.RUN and received a verdict of "no threats detected."
A technical walkthrough showed how to compile a Windows C program, add VERSIONINFO and ICON resources via a .rc file and MinGW-w64, and link them into a new PE executable. It emphasized that fields such as CompanyName and ProductName, as well as icons, are self-declared cosmetic resources and not proof of legitimacy or publisher identity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecocomelonc.github.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.