FILEMembers
FILE

Signed Adware Dropper Hits 39 Countries With 2/76 AV Detections

A trojanised BitComet installer signed with a commercially obtained Sectigo certificate is circulating across 39 countries, with its dropper component detected by just 2 of 76 antivirus engines. The campaign layers valid code-signing, sandbox-evasion instrumentation, and AWS CloudFront abuse to evade the triage filters most security teams apply to low-severity adware alerts.

Jun 19, 2026, 05:02 (UTC+9)Last seenJun 19, 2026Severity22ByCTX TeamIOC64MITRE48RegionsALBGBRBSCA

A trojanised BitComet installer bearing a commercially obtained Sectigo code-signing certificate is circulating across 39 countries, achieving a detection rate of just 2 out of 76 engines on its dropper component — not through novel exploitation or zero-day tradecraft, but through the deliberate layering of a valid certificate chain, sandbox-evasion instrumentation, and AWS CloudFront CDN abuse into what is, on the surface, a routine adware distribution campaign.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence