
A Builder Stub That Outlived Four Different Malware Labels
CTX Team traced Windows binaries tagged to APT28 activity back to two persistent build-pipeline fingerprints: a shared .NET imphash spanning XWorm, Amadey, and QCoin-branded loaders since 2017, and a Synaptics-branded dropper lineage locked to a forged 1992 compile timestamp. A lapsed 2019-2020 DigiCert EV certificate still trails one adware sample submitted as recently as mid-2026.
Cybercrime taxonomies love clean boundaries — XWorm here, Amadey there, a "msilheracles" trojan somewhere else. But a set of Windows binaries CTX Team has been tracking, tagged in upstream telemetry to APT28-associated activity, shows how thin those labels can be. Four samples that public detection engines classify as four unrelated families — a 2024 XWorm loader, a 2023 Amadey downloader, and two "QCoin"-branded .NET binaries dating back to December 2017 — all carry the exact same import-table…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read