FILEMembers
FILE

One Bundler, Four Fake Names, an APT28 Label That Doesn't Fit

A single Win32 installer disguised as PingInfoView, Roblox, a Portuguese renaming tool, and Microsoft PC Manager has surfaced 1,644 times across 1,438 sources. The pattern points to mass freeware-bundler distribution, not a targeted espionage lure.

Sep 14, 2026, 22:58 (UTC+9)Last seenSep 14, 2026Severity77ByCTX TeamActorAPT28StrontiumIOC11MITRE11

A single Win32 installer, 4.4 megabytes, has spent the past two years circulating under at least four different identities — a PingInfoView update, a Roblox Player installer, a Portuguese file-renaming tool called "renomear-tudo," and a Microsoft PC Manager setup package. All four are the same binary (imphash bdc39b1d…), repackaged under different display names and reused across 1,644 separate submissions from 1,438 unique sources.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence