
APT27's Godzilla Loader Factory: 18 Cloned Binaries, One C2 Gate
CTX Team's analysis of a 19-sample PE32 cluster reveals a production-grade payload generation pipeline attributed to APT27 with medium confidence, targeting Italy. Eighteen near-identical 9 KB loaders share a single imphash and YARA signature while carrying distinct fuzzy hashes, and all six active .ru C2 domains expose the same fixed campaign identifier at a uniform PHP gate.
Nineteen PE32 executables. One YARA rule. Six .ru domains. A single PHP gate path with a campaign identifier that never changes. What CTX Team's analysis of this cluster reveals is not a hastily assembled intrusion kit but the output of a production-grade payload generation pipeline — one where 18 structurally identical 9 KB binaries are stamped from a single build toolchain, each mutated just enough at the byte level to carry a distinct fuzzy hash while preserving an identical PE import table,…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read