
Signed LummaStealer Bundle Clears 76 AV Engines With DigiCert Certificate
A trojanised uTorrent installer served from AWS CloudFront drops a five-component .NET payload bundle signed under a legitimate Reason Cybersecurity Inc. DigiCert certificate, achieving zero detections across all 76 antivirus engines. The campaign combines PE timestamp stomping, anti-sandbox logic, and CDN-masquerading C2 nodes in Iceland and Singapore to harvest browser credentials across 52 countries.
Five Windows executables carrying a valid, unexpired Reason Cybersecurity Inc. code-signing certificate — all signed in a single session at 08:53 AM on May 26, 2026, under DigiCert Trusted G4 certificate serial 07 8A A6 13 E0 E5 D5 AB 31 96 67 B9 3D 2B 96 73 — have been circulating as the payload core of a LummaStealer distribution campaign that achieves zero detections across 76 antivirus engines. The delivery vehicle is a trojanised uTorrent installer signed by BitTorrent Inc.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read