APTMembers
APT

APT28 Hides RAT Stack Inside Trojanised Deepfake AI Tool

A 43 MB Windows executable posing as a popular open-source deepfake application drops VenomRAT, a clipboard hijacker, and a browser credential stealer onto victim machines. The campaign routes TLS-encrypted C2 traffic through Cloudflare-fronted Vietnam-registered infrastructure pre-provisioned two months before the malware cluster appeared, with a secondary Telegram API exfiltration channel providing redundancy.

Jun 4, 2026, 19:21 (UTC+9)Last seenJun 22, 2026Severity77ByCTX TeamActorAPT28StrontiumIOC15MITRE53RegionsNLTR

A 43-megabyte Windows executable named Deep-Live-Cam-VFX.exe — convincingly dressed as a popular open-source deepfake application — has been circulating across at least nine independent submission sources, carrying inside it a PyInstaller-packed payload cluster that drops VenomRAT, a clipboard hijacker, and a browser credential stealer onto victim machines.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence