C&CMembers
C&C

One DigiCert Cert Signed 16 Malicious Binaries Across 18 Months

A single code-signing certificate issued to a Chengdu-registered Chinese entity anchored an adware campaign spanning sixteen binaries and eight fake security-software personas. The certificate remained valid and unrevoked throughout, letting every payload pass sandbox checks with clean verdicts.

May 26, 2026, 22:40 (UTC+9)Last seenMay 26, 2026Severity100ByCTX TeamActorTA551ShathakIOC73MITRE12

Sixteen distinct Windows binaries. Eight separate product personas. One DigiCert code-signing certificate — and not a single revocation in eighteen months. That is the operational core of a sustained adware and data-harvesting campaign that CTX Team has been tracking across the Ludashi (鲁大师) software ecosystem, where malware dressed as Chinese security utilities has been circulating since at least November 2024.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence