FILEMembers
FILE

Trojanised BitComet Campaign Engineers 33-Engine Detection Gap via Shared Certificate

A dual-track payload chain signed by two commercial code-signing identities delivers DealPly adware and OfferCore bundleware to users across 75 countries. The operator deliberately paired a heavily flagged outer dropper with a near-clean inner stub signed by the same certificate, while AWS CloudFront fronting makes delivery-point blocking impractical.

May 31, 2026, 18:27 (UTC+9)Last seenMay 31, 2026Severity60ByCTX TeamIOC63MITRE4RegionsADAEALARAT

##A Certificate Hiding in Plain Sight: How a Trojanised BitComet Campaign Engineers Its Own Detection Gap Five Windows executables. Two code-signing identities. One AWS CloudFront subdomain. And a payload chain carefully tuned so that the component most likely to reach an endpoint registers a detection rate of just 2 out of 76 antivirus engines — while its outer wrapper, signed by the same certificate, flags on 35. That arithmetic is not an accident.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence