
Valid BitTorrent Certificate Smuggles Trojan Past Endpoint Defences
A trojanised uTorrent Web installer signed with a currently-valid BitTorrent Inc / DigiCert certificate is circulating as a dropper for a multi-stage payload chain. The campaign stacks three independent trust-subversion techniques — a legitimate code-signing credential, Amazon S3 staging, and scripted 30-day cert rotation on Hurricane Electric IPs — to defeat endpoint, network, and reputation controls simultaneously.
A trojanised uTorrent Web installer bearing a currently-valid BitTorrent Inc code-signing certificate — serial 07 57 ED 74 D0 2A B0 00 FE AB 74 59 A3 34 CB 63, issued by DigiCert and valid through 2026-12-16 — is circulating as a dropper for a multi-stage payload chain that combines living-off-trusted-infrastructure staging, a repurposed censorship-circumvention tool, and a scripted certificate-rotation playbook on adjacent Hurricane Electric addresses.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read