FILEMembers
FILE

Fake uTorrent Installers Pair Valid Code Signing With CDN Impersonation

A cluster of BitTorrent- and uTorrent-branded Windows installers is circulating alongside infrastructure using wildcard TLS certificates that impersonate Akamai, uTorrent, and Tencent Cloud CDN namespaces. One installer carries a currently valid BitTorrent Inc code-signing certificate yet still trips 20 of 75 AV engines as adware, while every network indicator sits at 0/91 detections.

Jun 23, 2026, 06:07 (UTC+9)Last seenJul 2, 2026Severity52ByCTX TeamIOC34MITRE46RegionsBRCACGCHCO

A cluster of Windows installers dressed up as the BitTorrent and uTorrent clients is circulating alongside a supporting network layer that borrows something rarely seen in commodity adware distribution: wildcard TLS certificates minted for someone else's brand. Three unrelated hosting providers — Digi Romania S.A. (AS8708, Romania), Advania Island ehf (AS50613, Iceland), and a Singapore-registered network called ACE (AS139341) — each present certificates whose subject lines point to major CDN…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence