
Signed Adware Dropper Hits 39 Countries With 2/76 AV Detections
A trojanised BitComet installer signed with a commercially obtained Sectigo certificate is circulating across 39 countries, with its dropper component detected by just 2 of 76 antivirus engines. The campaign layers valid code-signing, sandbox-evasion instrumentation, and AWS CloudFront abuse to evade the triage filters most security teams apply to low-severity adware alerts.
A trojanised BitComet installer bearing a commercially obtained Sectigo code-signing certificate is circulating across 39 countries, achieving a detection rate of just 2 out of 76 engines on its dropper component — not through novel exploitation or zero-day tradecraft, but through the deliberate layering of a valid certificate chain, sandbox-evasion instrumentation, and AWS CloudFront CDN abuse into what is, on the surface, a routine adware distribution campaign.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read