
Trojanised Dr.Fone Installer Delivers VjW0rm via Three-Continent CDN-Masquerade C2
A TA2541-linked campaign uses a pirated Wondershare Dr.Fone NSIS installer to drop a JavaScript worm that persists in the Windows Startup folder as 'Google Chrome.js'. Nine new file indicators and a third C2 IP have expanded the cluster, while the infrastructure's defining feature remains three geographically dispersed servers presenting wildcard TLS certificates impersonating Akamai, Alibaba CDN, and Tencent myqcloud.
Nine new file indicators and one additional command-and-control IP have been added to the TA2541-linked VjW0rm cluster since earlier coverage, expanding a campaign whose most operationally distinctive feature was never the payload itself but the infrastructure architecture surrounding it: three geographically dispersed servers, each presenting a wildcard-SAN TLS certificate impersonating a different major CDN brand, observed within a 48-hour window and spread across three separate autonomous…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read