Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Trojanised productivity apps: what controls are teams missing?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18936
Topic starter  

TL;DR: BaoLoader accounted for 13% of non-targeted malware in Q3 2025, according to Expel’s threat report, while related campaigns such as TamperedChef used functional apps and code-signing abuse to hide backdoors, execute commands, and spread through ordinary user downloads. The pattern shows that application control and software trust decisions now shape endpoint risk as much as classic malware detection.

NHIMG editorial — based on content published by Expel: Q3 2025 threat report part two on BaoLoader and related app-based malware activity

By the numbers:

Questions worth separating out

Q: What breaks when trojanised applications are not blocked on endpoints?

A: The control boundary between user intent and software behaviour breaks first.

Q: Why do deceptive productivity apps increase identity and access risk?

A: Because they inherit the rights of the user who launches them.

Q: How do security teams know if business application controls are working?

A: Look for three signals: fewer standing exceptions, cleaner SoD outcomes after role combination tests, and access review results that consistently remove unused permissions.

Practitioner guidance

  • Tighten application allowlisting for user endpoints Block installations of utilities that are not pre-approved, and review exceptions for browser extensions, PDF tools, and downloader apps that commonly masquerade as productivity software.
  • Detect script execution from low-trust software Alert when newly installed applications spawn PowerShell, enumerate antivirus products, or launch secondary payloads that are outside their declared business function.
  • Validate software provenance before approval Require publisher verification, code-signing checks, and change-review evidence for business apps sourced from ads, unofficial sites, or reseller channels.

What's in the full article

Expel's full blog covers the operational detail this post intentionally leaves for the source:

  • The quarter-by-quarter threat breakdown behind BaoLoader, TamperedChef, and related commodity malware activity.
  • The certificate-signing and certificate-revocation details that helped track campaign evolution over time.
  • The specific software families and distribution patterns used to spread fake productivity apps.
  • The researchers' reasoning on why LLMs may be lowering the cost of producing deceptive applications.

👉 Read Expel’s Q3 2025 threat report on BaoLoader and trojanised apps →

Trojanised productivity apps: what controls are teams missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18271
 

Trojanised productivity software is an application trust problem first and a malware problem second. The deceptive app pattern works because defenders often evaluate software by apparent function, not by the authority it gains after installation. Once a user accepts the binary, the malware inherits the endpoint context that the user already has. That makes software provenance, execution policy, and installation governance part of endpoint identity control, not separate concerns.

A question worth separating out:

Q: Who is accountable when a backdoored business app reaches a corporate endpoint?

A: Accountability usually spans endpoint security, application governance, and the business owner who approved the exception. If the organisation allows unsigned, weakly reviewed, or ad-sourced software, then the control failure is administrative as well as technical. Frameworks such as CIS Controls and NIST CSF place that responsibility on controlled software management and continuous monitoring.

👉 Read our full editorial: Trojanised apps and PUPs are blurring endpoint risk boundaries



   
ReplyQuote
Share: