APTMembers
APT

Fake Flash Installer Hides PlugX Loader With Timer-Based Sandbox Checks

A Nullsoft-packaged file posing as an Adobe Flash Player update reads the CPU clock and checks for debuggers before dropping its real payload. The stalling installer is the busiest piece in a small PlugX-linked set of three files and two parked domains tied together by shared tradecraft rather than shared infrastructure.

Aug 25, 2026, 22:29 (UTC+9)Last seenAug 25, 2026Severity77ByCTX TeamActorMustang PandaHoneyMyteIOC86MITRE20RegionsCH

A dropper calling itself install_flash_player.bin does something a real Adobe installer never does: it reads the CPU timer directly to work out whether it is being watched, checks for an attached debugger, and then simply waits — sometimes for long stretches — before it does anything else. Only after that stall completes does the Nullsoft-packaged installer (c56ac01b…) begin dropping its real payload.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence