
APT27 Toolkit Ties Six Malware Families to One C2 Cluster
Nine executables submitted to VirusTotal across five days share a reflective-loader stub, an identical EDR-bypass build fingerprint, and a single autonomous system for all C2 traffic. CTX Team's analysis reveals a purpose-built, multi-stage framework whose internal cohesion is visible only when evidence textures are read together.
Nine Windows executables submitted to VirusTotal across a five-day window in late May and early June 2026 do not look, at first glance, like a coordinated campaign. The threat labels scatter across the taxonomy — a banker trojan here, a clipboard hijacker there, an EDR-bypass pair, a StealC loader, an Amadey dropper. The file sizes range from 42 KB to 868 KB. No shared code-signing certificate ties them together.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read