
APT28 Hides RAT Stack Inside Trojanised Deepfake AI Tool
A 43 MB Windows executable posing as a popular open-source deepfake application drops VenomRAT, a clipboard hijacker, and a browser credential stealer onto victim machines. The campaign routes TLS-encrypted C2 traffic through Cloudflare-fronted Vietnam-registered infrastructure pre-provisioned two months before the malware cluster appeared, with a secondary Telegram API exfiltration channel providing redundancy.
A 43-megabyte Windows executable named Deep-Live-Cam-VFX.exe — convincingly dressed as a popular open-source deepfake application — has been circulating across at least nine independent submission sources, carrying inside it a PyInstaller-packed payload cluster that drops VenomRAT, a clipboard hijacker, and a browser credential stealer onto victim machines.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read