FILEMembers
FILE

Conduit-Signed Adware Dropper Achieved 6/54 Detections With Stomped Timestamps and C2 Victim Profiling

A 1.28 MB Windows installer signed with a legitimate Conduit Ltd. certificate suppressed detection by up to 50 antivirus engines while concealing a four-payload adware bundle. The campaign's command-and-control beacon encoded victim OS version and administrator privilege level as GET parameters before the server decided what to deliver, a structured triage technique unusual for adware distributors of the era.

May 31, 2026, 18:12 (UTC+9)Last seenMay 31, 2026Severity72ByCTX TeamIOC21MITRE22RegionsES

A 1.28 MB Windows executable signed with a then-valid Conduit Ltd. code-signing certificate achieved just 6 of 54 possible antivirus detections while concealing a compressed multi-payload bundle in a resource section registering entropy of 8.0 — the maximum possible for a randomly distributed byte stream. That single file, the entry point for a vigram-family adware campaign targeting technology-sector users in Spain, illustrates a layered evasion architecture that goes well beyond commodity…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence