
APTMembers
APTAPT28-Linked Loader Fires Amadey Signatures Despite DCRat Tag
A Win32 downloader tracked by CTX Team carries a DCRat family tag, a VirusTotal label of "abmrisk/common," and Amadey-specific Snort hits — all at once. The mismatch has held steady across two collection windows even as the file roster around it churned.
Jun 9, 2026, 23:05 (UTC+9)Last seenJul 2, 2026Severity77ByCTX TeamActorAPT28StrontiumIOC4MITRE25RegionsBDBFBRDZEG
A single Win32 executable now under continued watch by CTX Team carries three contradictory identities at once: the feed classifies it under the DCRat family, VirusTotal's own engines settle on the threat label "trojan.abmrisk/common," and the network traffic it generates fires Snort signatures written specifically for Amadey.
Members only
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to readSource: CTX Threat Intelligence