FILEMembers
FILE

Pay-Per-Install Campaign Adds CryptOne Dropper and Two C2 Domains in Nine Days

A pay-per-install adware operation has expanded sharply since prior coverage, provisioning two Cloudflare-proxied domains within nine days and adding a raw-IP payload endpoint on a Seychelles-registered host. The campaign has layered a CryptOne-packed downloader with active anti-sandbox behaviour onto its existing EV-signed adware chain, raising the possibility of a capability upgrade or third-party install-access sale.

May 30, 2026, 07:30 (UTC+9)Last seenMay 30, 2026Severity100ByCTX TeamIOC33MITRE31RegionsBREGGBPL

Since CTX Team's earlier coverage of this pay-per-install operation, the campaign has added ten new file indicators, stood up two freshly provisioned command-and-control domains within nine days of each other in May 2026, and introduced a raw-IP payload-delivery endpoint on a Netherlands-based host whose TLS certificate presents a deliberately misleading identity.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence