APTMembers
APT

Trojanised Dr.Fone Installer Delivers VjW0rm via Three-Continent CDN-Masquerade C2

A TA2541-linked campaign uses a pirated Wondershare Dr.Fone NSIS installer to drop a JavaScript worm that persists in the Windows Startup folder as 'Google Chrome.js'. Nine new file indicators and a third C2 IP have expanded the cluster, while the infrastructure's defining feature remains three geographically dispersed servers presenting wildcard TLS certificates impersonating Akamai, Alibaba CDN, and Tencent myqcloud.

May 29, 2026, 09:53 (UTC+9)Last seenJun 12, 2026Severity100ByCTX TeamActorTA2541Operation LayoverIOC23RegionsEGFRROUS

Nine new file indicators and one additional command-and-control IP have been added to the TA2541-linked VjW0rm cluster since earlier coverage, expanding a campaign whose most operationally distinctive feature was never the payload itself but the infrastructure architecture surrounding it: three geographically dispersed servers, each presenting a wildcard-SAN TLS certificate impersonating a different major CDN brand, observed within a 48-hour window and spread across three separate autonomous…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence