C&CMembers
C&C

Fake uTorrent Installer Uses Malformed Signature to Hide Decade-Old Adware

A Windows installer posing as uTorrent build 331 carries an Authenticode signature that fails validation outright, tied to a small purpose-built redirector cluster and flagged by 52 of 76 engines as InstallCore/DealPly adware. The case shows a decade-old trick — familiar branding plus a signature that merely looks legitimate — still working largely unchanged.

Jul 28, 2026, 05:37 (UTC+9)Last seenJul 28, 2026Severity100ByCTX TeamIOC15MITRE34RegionsBR

A Windows installer branded as uTorrent build 331 carries an Authenticode signature that fails validation outright — VirusTotal's own signing verdict states plainly that "the digital signature of the object is malformed," pointing analysts to the decade-old Microsoft security bulletin MS13-098 that documented exactly this class of forgeable signature block.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence