FILEMembers
FILE

Validly Signed uTorrent Installer Hides Trojanized Adware Payload

A fully valid BitTorrent Inc/DigiCert-signed uTorrent Classic installer is spreading malware that only 22 of 76 antivirus engines catch, while an unsigned packed sibling from the same build lineage evades all but 4 of 75. Both ride alongside TLS infrastructure spoofing utorrent.com and Tencent's myqcloud.com CDN.

Jun 10, 2026, 23:07 (UTC+9)Last seenJul 2, 2026Severity100ByCTX TeamIOC34RegionsAEALARATAU

A Windows installer carrying a fully valid BitTorrent Inc / DigiCert code-signing chain is circulating as a trojanized uTorrent Classic setup — flagged malicious by 22 of 76 antivirus engines even though every certificate check in the chain returns clean. The same build lineage produced an unsigned, PEiD-packed sibling that only 4 of 75 engines catch.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence