
Fake YCleaner Hides PowerShell Fetch Loop Behind Spoofed AV Certificate
A phony system-cleaner tool called YCleaner drops a PowerShell-based downloader chain that reuses one sandbox signature across three separate binaries, staging a payload inside a ZIP that zero of 77 scanners flag. The domain feeding it, adobehelp.net, has DNS records that contradict its own WHOIS listing.
A "system cleaner" branded YCleaner wraps a multi-stage dropper chain that leans on a spoofed antivirus-vendor certificate and a single PowerShell-invoked downloader signature reused across three separate binaries — and stages its final payload inside a ZIP archive that, as of this writing, zero of 77 scanning engines flag as malicious. The domain feeding the chain, adobehelp.net, carries a nameserver record that contradicts its own WHOIS listing.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read