
Pay-Per-Install Campaign Adds CryptOne Dropper and Two C2 Domains in Nine Days
A pay-per-install adware operation has expanded sharply since prior coverage, provisioning two Cloudflare-proxied domains within nine days and adding a raw-IP payload endpoint on a Seychelles-registered host. The campaign has layered a CryptOne-packed downloader with active anti-sandbox behaviour onto its existing EV-signed adware chain, raising the possibility of a capability upgrade or third-party install-access sale.
Since CTX Team's earlier coverage of this pay-per-install operation, the campaign has added ten new file indicators, stood up two freshly provisioned command-and-control domains within nine days of each other in May 2026, and introduced a raw-IP payload-delivery endpoint on a Netherlands-based host whose TLS certificate presents a deliberately misleading identity.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read