Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Fondue.exe Exploited for Malware Deployment

Microsoft Fondue.exe Exploited for Malware Deployment

Posted on June 18, 2026 By CWS

Cybersecurity researchers have identified a new attack strategy involving the misuse of a lesser-known Windows executable. Hackers are exploiting Fondue.exe, a genuine Microsoft utility, to covertly load a malicious control panel file named APPWIZ.cpl, thereby facilitating the stealthy installation of malware on victim systems.

Exploitation of Fondue.exe

This sophisticated method leverages a trusted system binary, making detection by conventional security software more challenging. The attack commences with the deployment of a deceptive MSI installer, masquerading as legitimate software, which is distributed via fraudulent websites mimicking authentic developer resources. Upon execution, this installer deposits several files into a concealed directory, including the legitimate Fondue.exe binary and a compromised version of APPWIZ.cpl, equipped with obfuscation mechanisms.

The attackers aim to render the procedure indistinguishable from regular system operations. Trend Micro’s report, shared with Cyber Security News (CSN), highlights an increasing trend among advanced threat groups to exploit legitimate Windows binaries. This tactic effectively circumvents security measures by hiding behind trusted processes.

Targets and Methodology

The threat actors behind this campaign, tracked by intelligence teams, are employing generative AI to expedite the development of attack tools, indicating a concerning advancement in their capabilities. The campaign primarily targets governmental bodies, military personnel, and professionals in drone manufacturing and engineering sectors.

Attackers have used fake Starlink registration services and drone pilot training applications to deceive victims into running the malicious installers. These carefully crafted decoys appear highly credible to their intended targets, posing significant risks in environments where operational precision is critical.

Technical Details and Defense Strategies

Fondue.exe, known as the ‘Features on Demand UX’ application, is exploited by placing a rogue APPWIZ.cpl file in the same directory, which diverts the system’s binary loading process. This malicious file is protected using UPX compression and Oreans Code Virtualizer, complicating reverse engineering efforts.

Once embedded, the malware establishes persistence by creating a scheduled task that mimics legitimate system activities. This task connects to the attackers’ command-and-control server, facilitating long-term espionage activities. Security experts recommend vigilant monitoring of Fondue.exe execution outside standard directories and deploying endpoint detection systems to flag suspicious DLL and CPL side-loading behaviors.

The use of AI in crafting malware signifies a shift in threat dynamics, reducing barriers for attackers to develop sophisticated implants. Organizations are advised to remain cautious of software installations from unofficial sources, even when they appear legitimate.

The ongoing exploitation of authentic Windows binaries for malicious purposes underscores the effectiveness of such tactics among advanced persistent threats. Security measures should prioritize behavioral indicators over file-level signatures to enhance detection capabilities.

Cyber Security News Tags:APPWIZ.cpl, cyber attack, cyber threats, Cybersecurity, Fondue.exe, malicious software, Malware, Microsoft, security tools, Threat Actors

Post navigation

Previous Post: Apple SoCs Vulnerable to New BootROM Exploit
Next Post: F5 Fixes Critical NGINX Vulnerabilities Allowing Code Execution

Related Posts

North Korean Kimsuky and Lazarus Join Forces to Exploit Zero-Day Vulnerabilities Targeting Critical Sectors Worldwide North Korean Kimsuky and Lazarus Join Forces to Exploit Zero-Day Vulnerabilities Targeting Critical Sectors Worldwide Cyber Security News
Chinese Hacker Linked to Cyber Espionage Extradited to U.S. Chinese Hacker Linked to Cyber Espionage Extradited to U.S. Cyber Security News
LapDogs Hackers Leverages 1,000 SOHO Devices Using a Custom Backdoor to Act Covertly LapDogs Hackers Leverages 1,000 SOHO Devices Using a Custom Backdoor to Act Covertly Cyber Security News
Microsoft Warns Windows Systems May Enter BitLocker Recovery After October 2025 Updates Microsoft Warns Windows Systems May Enter BitLocker Recovery After October 2025 Updates Cyber Security News
251 Malicious IPs Attacking Cloud-Based Devices Leveraging 75 Exposure Points 251 Malicious IPs Attacking Cloud-Based Devices Leveraging 75 Exposure Points Cyber Security News
New Rust Based InfoStealer Extracts Sensitive Data from Chromium-based Browsers New Rust Based InfoStealer Extracts Sensitive Data from Chromium-based Browsers Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F5 Fixes Critical NGINX Vulnerabilities Allowing Code Execution
  • Microsoft Fondue.exe Exploited for Malware Deployment
  • Apple SoCs Vulnerable to New BootROM Exploit
  • Outdated REDCap Servers Pose Cybersecurity Risks
  • INC Ransomware Dominates 2026 with Over 830 Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F5 Fixes Critical NGINX Vulnerabilities Allowing Code Execution
  • Microsoft Fondue.exe Exploited for Malware Deployment
  • Apple SoCs Vulnerable to New BootROM Exploit
  • Outdated REDCap Servers Pose Cybersecurity Risks
  • INC Ransomware Dominates 2026 with Over 830 Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark