APTMembers
APT

APT28-Linked Loader Fires Amadey Signatures Despite DCRat Tag

A Win32 downloader tracked by CTX Team carries a DCRat family tag, a VirusTotal label of "abmrisk/common," and Amadey-specific Snort hits — all at once. The mismatch has held steady across two collection windows even as the file roster around it churned.

Jun 9, 2026, 23:05 (UTC+9)Last seenJul 2, 2026Severity77ByCTX TeamActorAPT28StrontiumIOC4MITRE25RegionsBDBFBRDZEG

A single Win32 executable now under continued watch by CTX Team carries three contradictory identities at once: the feed classifies it under the DCRat family, VirusTotal's own engines settle on the threat label "trojan.abmrisk/common," and the network traffic it generates fires Snort signatures written specifically for Amadey.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence