APTMembers
APT

A Builder Fingerprint Ties Three 'Different' Trojans to One Assembly Line

Three files labeled as separate threats — jalapeno, AgentTesla and zusy — share one identical import hash, revealing a common .NET builder behind them. Detection engines are naming surface behavior while the import table exposes a single crimeware-as-a-service production line underneath.

Aug 29, 2026, 22:36 (UTC+9)Last seenAug 29, 2026Severity82ByCTX TeamActorOperation Black AtlasIOC37MITRE51

Three files carrying three unrelated threat labels — trojan.msil/jalapeno, trojan.msil/agenttesla and trojan.msil/zusy — turn out, on inspection of their import tables, to be the same product line. Each one carries the identical import hash f34d5f2d4577ed6d9ceec516c1f5a744, a fingerprint of the exact function-import list a .NET builder or crypter service stamps into every executable it produces.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence