APTMembers
APT

Trojanised Adobe Firefly Installer Runs Triple-Monetisation Kill Chain on Construction Firms

A campaign active since September 2023 is distributing a fake Adobe Firefly AI installer that deploys a BYOVD kernel driver, PureLogs credential stealer, and Nanopool crypto-miner simultaneously. Construction-sector targets in Brazil, Germany, and Luxembourg face a three-stream monetisation model that keeps generating revenue even when individual components are detected and removed.

Jun 23, 2026, 00:58 (UTC+9)Last seenJun 23, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC34RegionsBRDELU

Pirated creative software has long been a reliable vector for commodity malware, but a campaign CTX Team has been tracking shows how far that distribution model has matured. Two oversized Windows executables — both named FireflyAI.exe, one weighing 45 MB and the other 53 MB — are circulating as trojanised installers for Adobe's Firefly AI tool, with one sample's embedded path string explicitly referencing "Firefly AI 25.0.0.2265 beta for Adobe Photoshop 24.7 (x64)." The lure has been active…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence