APTMembers
APT

19 Trojanized IME Files Share One DigiCert Cert, Route C2 Through China's Largest CDN

Nineteen Windows executables masquerading as a Chinese input-method suite carried a single valid DigiCert code-signing certificate, producing clean sandbox verdicts despite detection by up to 54 of 79 AV engines. Malicious network traffic was routed through Wangsu ChinaNetCenter CDN infrastructure shared with Meituan, Dianping, and other major Chinese consumer platforms, making IP-layer blocking operationally costly.

Jun 4, 2026, 23:13 (UTC+9)Last seenJun 4, 2026Severity94ByCTX TeamActorSalty SpiderKuKuIOC33MITRE10

##One Certificate, Nineteen Payloads: How a Wubi IME Trojan Hides Behind a Valid DigiCert Signature and China's Largest CDN Nineteen Windows executables — all masquerading as the 万能五笔输入法 (WanNeng Wubi IME) Chinese input-method suite and all carrying a single valid DigiCert code-signing certificate issued to Shanghai Oriental Webcasting Co. Ltd.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence