
Trojanised BitTorrent Installer Evades 74 of 75 AV Engines in 33-Country Campaign
A 4.3 MB Windows executable dressed in full BitTorrent branding achieves a 1-in-75 detection rate while routing harvested credentials to an Iceland colocation block whose servers answer with a *.utorrent.com TLS certificate. The campaign layers a PEiD-packed zero-import installer, P2P-branded exfiltration endpoints, and DGA-labelled AWS CloudFront subdomains into a three-tier evasion stack targeting government, media, technology, and telecom organisations across 33 countries.
A 4.3 MB Windows executable presenting full BitTorrent branding — product name "BT® Classic," version 51.1054.0.0, copyright "©2026 BitTorrent Limited" — is circulating as a trojanised installer that achieves a 1-in-75 detection rate while routing harvested credentials to a colocation block in Iceland whose servers answer with a *.utorrent.com TLS certificate.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read