
One DigiCert Cert, 14 Executables, Nine Months Undetected
A single code-signing certificate issued to a Chengdu-registered entity has anchored a nine-month adware pipeline producing 14 distinct Windows binaries under six product personas. Sandbox environments return clean verdicts while static engines flag the same files at rates up to 34 of 76, a gap sustained by stacked evasion layers including PE overlay concealment and C2 traffic hidden behind UnionPay financial-sector TLS certificates.
Fourteen distinct Windows executables. Six different product personas. One code-signing certificate — and nine months of continuous, largely undetected operation. That is the operational picture CTX Team has assembled from a cluster of signed PE32 binaries circulating through the Ludashi PUA distribution ecosystem, all stamped with a single DigiCert certificate issued to the Chengdu-registered entity 成都奇鲁科技有限公司 (serial 0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98, valid through 2027-05-20).
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read