APTMembers
APT

Signed 'PC Cleaner' DLLs Flagged as PubNubRAT by Sandbox Engine

A WinOptimize-branded optimizer bundle from the Ludashi adware lineage ships two digitally signed DLLs that one malware sandbox classifies outright as the PubNubRAT remote-access trojan, even as roughly two-thirds of static antivirus engines still tag them as ordinary adware. The split verdict exposes a detection blind spot between static PUA labels and dynamic behavioral analysis.

Aug 22, 2026, 14:30 (UTC+9)Last seenAug 22, 2026Severity100ByCTX TeamActorTA428ThunderCatsIOC39MITRE24

A system-optimizer bundle marketed under the WinOptimize brand carries two DLLs that a dedicated malware sandbox names as a remote-access trojan called "PubNubRAT" — even though both files are digitally signed and roughly two-thirds of static antivirus engines wave them through as ordinary adware. The privacy.dll component (82c06ae2…f0928) triggers a malicious verdict from the C2AE sandbox, which classifies it outright as a RAT and names PubNubRAT as the payload family; a second DLL from the…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence