
Three Unrelated Trojans Hit in 48 Hours, One Fake Mail Server Behind Them
Agent Tesla/Etecer, ModiLoader, and an obfuscated Luainj loader surfaced within a single 48-hour window, sharing no code, signer, or import hash. All three point to one piece of infrastructure — trimnt.com and 45.66.248.2 — provisioned and certified as a mail server weeks before any sample appeared.
Between August 10 and August 11, 2026, three completely unrelated pieces of commodity malware surfaced in rapid succession — a JavaScript downloader carrying an Agent Tesla/Etecer label, a RAR-packaged ModiLoader dropper, and a heavily obfuscated JavaScript file tagged Luainj — none of them sharing an import hash, a code signer, or even a threat family name with the others.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read