
Signed Adware Cluster Hides Confirmed RAT Behind Chengdu Shell Certs
A 26-file Windows utility cluster branded DllFix, WinClean, ZXStoreX and PicSnapX rotates between two Chengdu-registered code-signing identities that both chain to the same DigiCert root, keeping distribution running even as one certificate lapses. At least one signed DLL in that same cohort triggered a sandbox-confirmed remote-access-trojan verdict rather than the usual adware payload.
A 26-file cluster of Windows utility installers — branded as DllFix, WinClean, ZXStoreX and PicSnapX — is being distributed under two rotating Chinese corporate code-signing identities that both terminate in the identical certificate authority chain, and at least one binary from that signed cohort has triggered a sandbox-confirmed remote-access-trojan verdict rather than the run-of-the-mill adware payload the rest of the set carries.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read