
APT28 Hides Trojan in Pirated Software, Spreads via USB Across 22 Countries
A fake FL Studio installer carrying an invalid code-signing certificate and a three-layer evasion stack is circulating across manufacturing and telecom networks in 22 countries. The malware executes through WMI, copies itself to USB drives, and beacons to a Ukraine-hosted C2 cluster pre-staged seven weeks before the payload appeared.
A 2,967-kilobyte Windows executable dressed up as "FL Studio 2025 Full Version.exe" is circulating across manufacturing and telecom networks in 22 countries, carrying a layered evasion stack that defeated one of three automated sandboxes outright — and the certificate stapled to it was issued the same day the file first appeared on VirusTotal, minted by a service that signs anything you give it.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read