
One DigiCert Cert Signed 16 Malicious Binaries Across 18 Months
A single code-signing certificate issued to a Chengdu-registered Chinese entity anchored an adware campaign spanning sixteen binaries and eight fake security-software personas. The certificate remained valid and unrevoked throughout, letting every payload pass sandbox checks with clean verdicts.
Sixteen distinct Windows binaries. Eight separate product personas. One DigiCert code-signing certificate — and not a single revocation in eighteen months. That is the operational core of a sustained adware and data-harvesting campaign that CTX Team has been tracking across the Ludashi (鲁大师) software ecosystem, where malware dressed as Chinese security utilities has been circulating since at least November 2024.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read