
Trojanised Adobe Firefly Installer Runs Triple-Monetisation Kill Chain on Construction Firms
A campaign active since September 2023 is distributing a fake Adobe Firefly AI installer that deploys a BYOVD kernel driver, PureLogs credential stealer, and Nanopool crypto-miner simultaneously. Construction-sector targets in Brazil, Germany, and Luxembourg face a three-stream monetisation model that keeps generating revenue even when individual components are detected and removed.
Pirated creative software has long been a reliable vector for commodity malware, but a campaign CTX Team has been tracking shows how far that distribution model has matured. Two oversized Windows executables — both named FireflyAI.exe, one weighing 45 MB and the other 53 MB — are circulating as trojanised installers for Adobe's Firefly AI tool, with one sample's embedded path string explicitly referencing "Firefly AI 25.0.0.2265 beta for Adobe Photoshop 24.7 (x64)." The lure has been active…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read