FILEMembers
FILE

Trojanised BitTorrent Installer Evades 74 of 75 AV Engines in 33-Country Campaign

A 4.3 MB Windows executable dressed in full BitTorrent branding achieves a 1-in-75 detection rate while routing harvested credentials to an Iceland colocation block whose servers answer with a *.utorrent.com TLS certificate. The campaign layers a PEiD-packed zero-import installer, P2P-branded exfiltration endpoints, and DGA-labelled AWS CloudFront subdomains into a three-tier evasion stack targeting government, media, technology, and telecom organisations across 33 countries.

Jun 28, 2026, 02:17 (UTC+9)Last seenJun 28, 2026Severity100ByCTX TeamIOC60MITRE70RegionsADARATBABD

A 4.3 MB Windows executable presenting full BitTorrent branding — product name "BT® Classic," version 51.1054.0.0, copyright "©2026 BitTorrent Limited" — is circulating as a trojanised installer that achieves a 1-in-75 detection rate while routing harvested credentials to a colocation block in Iceland whose servers answer with a *.utorrent.com TLS certificate.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence