
One DigiCert Certificate Signed 13 Chinese Adware Builds for 18 Months
A single code-signing certificate tied to 成都奇鲁科技有限公司 has quietly signed thirteen Win32 'system optimizer' and browser-assistant binaries since November 2024, letting them slip past roughly half of AV engines with zero malicious sandbox verdicts. The same dataset shows sixteen unrelated Chinese ISP IPs cloning a UnionPay International TLS certificate, pointing to a shared trust-abuse infrastructure rather than a targeted intrusion.
The most durable artifact in this dataset isn't a zero-day or a novel loader — it's a single DigiCert-issued code-signing certificate that has quietly signed thirteen different Win32 binaries over eighteen months, from November 2024 through May 2026. The signer of record is 成都奇鲁科技有限公司, and the certificate — serial 0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98, chained through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 up to DigiCert Trusted Root G4 — has stayed valid and in…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read