APTMembers
APT

Decade-Old Flash Exploit Rides Along With Game-Trainer Loader

A Vietnamese-language auto-trainer toolkit for Vo Lam Truyen Ky bundles a packed loader, VulanPK.exe, with an exploit DLL still carrying the fingerprint of CVE-2015-2387, an 11-year-old Adobe Flash vulnerability. The two files share a 2018 compile timestamp and build path, distributed via two freshly registered domains behind identical MegaDNS nameservers.

Sep 3, 2026, 22:28 (UTC+9)Last seenSep 3, 2026Severity67ByCTX TeamActorBlueBottleOpera1erIOC86MITRE35RegionsAT

A Vietnamese-language "auto-trainer" toolkit for the online game Vo Lam Truyen Ky is quietly bundling something considerably nastier than a speed-hack: a packed loader called VulanPK.exe paired, byte for byte in the same build directory, with an exploit DLL that still carries the fingerprint of a 2015 Adobe Flash Player vulnerability.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence