
One Code-Signing Cert, 15 Malware Families, Valid Until 2027
A DigiCert certificate issued to a Chinese commercial entity has signed 15 malicious executables across six threat families over twelve months — and remains valid through May 2027. The campaign exploits Windows Authenticode trust to bypass OS-level gatekeeping on endpoints lacking application allowlisting, while sandbox-evasion logic keeps dynamic detection rates at zero.
A single DigiCert code-signing certificate issued to a Chinese commercial entity has been used to sign 15 distinct malicious PE32 executables spanning six threat families over a twelve-month window — and it remains valid through May 2027. The certificate, issued to 成都奇鲁科技有限公司 (serial 0D078E70EAEE48FFEB9576BDD400BE98, thumbprint EC5BB0C4BE5D6F7CD9D863D6585CF1F3EF58FDA0), has functioned as a persistent OS-level trust bypass [T1553.002] across the entire payload portfolio, enabling malicious…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read