APTMembers
APT

Three Unrelated Trojans Hit in 48 Hours, One Fake Mail Server Behind Them

Agent Tesla/Etecer, ModiLoader, and an obfuscated Luainj loader surfaced within a single 48-hour window, sharing no code, signer, or import hash. All three point to one piece of infrastructure — trimnt.com and 45.66.248.2 — provisioned and certified as a mail server weeks before any sample appeared.

Aug 21, 2026, 22:58 (UTC+9)Last seenSep 14, 2026Severity100ByCTX TeamActorTA505Hive0065IOC7RegionsAUCHDEESGR

Between August 10 and August 11, 2026, three completely unrelated pieces of commodity malware surfaced in rapid succession — a JavaScript downloader carrying an Agent Tesla/Etecer label, a RAR-packaged ModiLoader dropper, and a heavily obfuscated JavaScript file tagged Luainj — none of them sharing an import hash, a code signer, or even a threat family name with the others.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence