C&CMembers
C&C

Signed Adware Cluster Hides Confirmed RAT Behind Chengdu Shell Certs

A 26-file Windows utility cluster branded DllFix, WinClean, ZXStoreX and PicSnapX rotates between two Chengdu-registered code-signing identities that both chain to the same DigiCert root, keeping distribution running even as one certificate lapses. At least one signed DLL in that same cohort triggered a sandbox-confirmed remote-access-trojan verdict rather than the usual adware payload.

Jul 19, 2026, 21:40 (UTC+9)Last seenJul 19, 2026Severity100ByCTX TeamActorPatchworkChinastratsIOC73

A 26-file cluster of Windows utility installers — branded as DllFix, WinClean, ZXStoreX and PicSnapX — is being distributed under two rotating Chinese corporate code-signing identities that both terminate in the identical certificate authority chain, and at least one binary from that signed cohort has triggered a sandbox-confirmed remote-access-trojan verdict rather than the run-of-the-mill adware payload the rest of the set carries.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence