C&CMembers
C&C

APT27 Toolkit Ties Six Malware Families to One C2 Cluster

Nine executables submitted to VirusTotal across five days share a reflective-loader stub, an identical EDR-bypass build fingerprint, and a single autonomous system for all C2 traffic. CTX Team's analysis reveals a purpose-built, multi-stage framework whose internal cohesion is visible only when evidence textures are read together.

Jun 7, 2026, 03:54 (UTC+9)Last seenJun 7, 2026Severity100ByCTX TeamActorAPT27TEMP.HippoIOC74RegionsDZ

Nine Windows executables submitted to VirusTotal across a five-day window in late May and early June 2026 do not look, at first glance, like a coordinated campaign. The threat labels scatter across the taxonomy — a banker trojan here, a clipboard hijacker there, an EDR-bypass pair, a StealC loader, an Amadey dropper. The file sizes range from 42 KB to 868 KB. No shared code-signing certificate ties them together.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence