APTMembers
APT

Fake YCleaner Hides PowerShell Fetch Loop Behind Spoofed AV Certificate

A phony system-cleaner tool called YCleaner drops a PowerShell-based downloader chain that reuses one sandbox signature across three separate binaries, staging a payload inside a ZIP that zero of 77 scanners flag. The domain feeding it, adobehelp.net, has DNS records that contradict its own WHOIS listing.

Aug 5, 2026, 05:34 (UTC+9)Last seenAug 5, 2026Severity100ByCTX TeamActorBlueBottleOpera1erIOC19MITRE29RegionsMY

A "system cleaner" branded YCleaner wraps a multi-stage dropper chain that leans on a spoofed antivirus-vendor certificate and a single PowerShell-invoked downloader signature reused across three separate binaries — and stages its final payload inside a ZIP archive that, as of this writing, zero of 77 scanning engines flag as malicious. The domain feeding the chain, adobehelp.net, carries a nameserver record that contradicts its own WHOIS listing.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence