APTMembers
APT

NullMixer Bundle Drops Five Malware Families via Discord Fake Installer

A single fake Windows installer unpacks RedlineStealer, ClipBanker, SmokeLoader, StealBit, and Upatre simultaneously rather than sequentially. The campaign, targeting Bolivian endpoints, is backed by a three-node Singapore proxy cluster and infrastructure maintained continuously since August 2021.

Jun 18, 2026, 04:04 (UTC+9)Last seenJun 18, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC35RegionsBO

A single Windows executable masquerading as a software setup wizard unpacks at least five distinct malware families the moment a user double-clicks it — RedlineStealer, ClipBanker, SmokeLoader, StealBit, and Upatre arriving as a coordinated bundle rather than a sequential chain. That delivery model, confirmed by the Malpedia YARA rule win_nullmixer_auto firing on two large installer files and by unanimous sandbox verdicts naming four families simultaneously, is the operationally distinctive…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence