APTMembers
APT

A 2020 Loader Stub Still Circulates in Fresh Detections Today

Twenty file indicators tied to Ramsay- and DarkHotel-labeled trojans trace back to a single unmodified build compiled 2020-03-04, still surfacing in new submissions as of December 2025. Rather than rebuilding its toolkit, the operator keeps redeploying the identical loader dressed up with borrowed UAC-bypass and reflective-injection modules.

Aug 12, 2026, 06:37 (UTC+9)Last seenAug 12, 2026Severity82ByCTX TeamActorDarkHotelFallout TeamIOC21MITRE11RegionsPH

Twenty file indicators tied to Ramsay- and DarkHotel-labeled trojans converge on a single, unmodified compiled artifact: an import-table fingerprint of 34791a1ad0a42b816d48d1d1c182fe7d and a Rich PE header hash of d9068e3808ee41e8c6f32c9fd4e83a79, both frozen to a compile timestamp of 2020-03-04. That exact build keeps resurfacing under new detections as late as December 2025 — five years after it was compiled — wearing four different VirusTotal threat labels along the way.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence