FILEMembers
FILE

Fireball/Elex Adware: 14 DLLs Built in a Four-Day Cycle

A cluster of unsigned Windows DLLs compiled within a four-day window in January 2017 shares a builder fingerprint tight enough to trace to a single toolkit. Filename-matched YARA rules, a shared vhash skeleton, and a reused service-path string tie the cohort to the Fireball/Elex/Sasquor adware family rather than a bespoke intrusion set.

Jul 17, 2026, 14:59 (UTC+9)Last seenJul 17, 2026Severity22ByCTX TeamActorBariumWicked SpiderIOC30MITRE43RegionsBRPK

A cluster of fourteen unsigned Windows DLLs — plus one companion executable — compiled between January 23 and January 26, 2017 shares a builder fingerprint tight enough to read like a single production run. The modules carry deliberately mundane names: RegKey.dll, Skytech.dll, ClearLog.dll, Packet.dll, MIO.dll, Berserker.dll, Install.dll, Lancer.dll, At.dll, and a standalone WinTooll.exe. None are signed.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence