APTMembers
APT

Same Evasion Trick, Same Compiler Run, Tie Five Files Together

Three unrelated VirusTotal-labeled Trojans — a clipboard hijacker, a dropper, and a lateral-spreading DLL — share an identical debugger-check-and-stall evasion pattern that fooled sandboxes even as dozens of static engines flagged them. Two clipbanker builds trace to the exact same compiler run, pointing to a small operation reusing one toolchain across disposable payloads.

Aug 17, 2026, 22:29 (UTC+9)Last seenAug 17, 2026Severity58ByCTX TeamActorAPT28StrontiumIOC65MITRE66RegionsJONLROSA

Three files in this cluster carry three different VirusTotal threat labels — a clipboard-hijacking banker, a generic dropper, and a DLL flagged for lateral spread — yet all three share the identical pair of behavioural tags: a check for whether a debugger is attached, and a routine that stalls for long periods before doing anything else. That repetition, sitting underneath payloads that otherwise look unrelated, is the more interesting story here than any single malware family.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence