APTMembers
APT

APT27's Godzilla Loader Factory: 18 Cloned Binaries, One C2 Gate

CTX Team's analysis of a 19-sample PE32 cluster reveals a production-grade payload generation pipeline attributed to APT27 with medium confidence, targeting Italy. Eighteen near-identical 9 KB loaders share a single imphash and YARA signature while carrying distinct fuzzy hashes, and all six active .ru C2 domains expose the same fixed campaign identifier at a uniform PHP gate.

Jun 14, 2026, 10:17 (UTC+9)Last seenJun 14, 2026Severity100ByCTX TeamActorAPT27TEMP.HippoIOC64MITRE9RegionsIT

Nineteen PE32 executables. One YARA rule. Six .ru domains. A single PHP gate path with a campaign identifier that never changes. What CTX Team's analysis of this cluster reveals is not a hastily assembled intrusion kit but the output of a production-grade payload generation pipeline — one where 18 structurally identical 9 KB binaries are stamped from a single build toolchain, each mutated just enough at the byte level to carry a distinct fuzzy hash while preserving an identical PE import table,…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence