APTMembers
APT

A Builder Stub That Outlived Four Different Malware Labels

CTX Team traced Windows binaries tagged to APT28 activity back to two persistent build-pipeline fingerprints: a shared .NET imphash spanning XWorm, Amadey, and QCoin-branded loaders since 2017, and a Synaptics-branded dropper lineage locked to a forged 1992 compile timestamp. A lapsed 2019-2020 DigiCert EV certificate still trails one adware sample submitted as recently as mid-2026.

Aug 3, 2026, 21:35 (UTC+9)Last seenAug 3, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC50MITRE100

Cybercrime taxonomies love clean boundaries — XWorm here, Amadey there, a "msilheracles" trojan somewhere else. But a set of Windows binaries CTX Team has been tracking, tagged in upstream telemetry to APT28-associated activity, shows how thin those labels can be. Four samples that public detection engines classify as four unrelated families — a 2024 XWorm loader, a 2023 Amadey downloader, and two "QCoin"-branded .NET binaries dating back to December 2017 — all carry the exact same import-table…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence