FILEMembers
FILE

Signed LummaStealer Bundle Clears 76 AV Engines With DigiCert Certificate

A trojanised uTorrent installer served from AWS CloudFront drops a five-component .NET payload bundle signed under a legitimate Reason Cybersecurity Inc. DigiCert certificate, achieving zero detections across all 76 antivirus engines. The campaign combines PE timestamp stomping, anti-sandbox logic, and CDN-masquerading C2 nodes in Iceland and Singapore to harvest browser credentials across 52 countries.

May 30, 2026, 11:53 (UTC+9)Last seenMay 30, 2026Severity28ByCTX TeamIOC72MITRE49RegionsAEARATAUBA

Five Windows executables carrying a valid, unexpired Reason Cybersecurity Inc. code-signing certificate — all signed in a single session at 08:53 AM on May 26, 2026, under DigiCert Trusted G4 certificate serial 07 8A A6 13 E0 E5 D5 AB 31 96 67 B9 3D 2B 96 73 — have been circulating as the payload core of a LummaStealer distribution campaign that achieves zero detections across 76 antivirus engines. The delivery vehicle is a trojanised uTorrent installer signed by BitTorrent Inc.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence