APTMembers
APT

APT28 Hides Trojan in Pirated Software, Spreads via USB Across 22 Countries

A fake FL Studio installer carrying an invalid code-signing certificate and a three-layer evasion stack is circulating across manufacturing and telecom networks in 22 countries. The malware executes through WMI, copies itself to USB drives, and beacons to a Ukraine-hosted C2 cluster pre-staged seven weeks before the payload appeared.

Jun 20, 2026, 16:10 (UTC+9)Last seenJun 20, 2026Severity77ByCTX TeamActorAPT28StrontiumIOC8MITRE11RegionsAOARAUBOBR

A 2,967-kilobyte Windows executable dressed up as "FL Studio 2025 Full Version.exe" is circulating across manufacturing and telecom networks in 22 countries, carrying a layered evasion stack that defeated one of three automated sandboxes outright — and the certificate stapled to it was issued the same day the file first appeared on VirusTotal, minted by a service that signs anything you give it.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence