FILEMembers
FILE

Validly Signed uTorrent Installer Hides Trojan.Offercore

A `utorrent_installer.exe` carries a fully valid BitTorrent Inc/DigiCert signature chain, yet 18 of 76 engines flag it as trojan.offercore. The payload leans on anti-sandbox timing and P2P-mimicking traffic to slip past defenses that trust signed code.

Aug 4, 2026, 13:47 (UTC+9)Last seenAug 4, 2026Severity74ByCTX TeamIOC34MITRE48RegionsADAEALAMAR

An executable calling itself utorrent_installer.exe carries a fully valid four-tier code-signing chain — BitTorrent Inc, chained up through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 to DigiCert Trusted Root G4 — and yet 18 of 76 engines still flag it as trojan.offercore/r783575. That combination is the story here: not a forged certificate, but a genuine one riding on top of a payload the security industry has learned to distrust.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence