
19 Trojanized IME Files Share One DigiCert Cert, Route C2 Through China's Largest CDN
Nineteen Windows executables masquerading as a Chinese input-method suite carried a single valid DigiCert code-signing certificate, producing clean sandbox verdicts despite detection by up to 54 of 79 AV engines. Malicious network traffic was routed through Wangsu ChinaNetCenter CDN infrastructure shared with Meituan, Dianping, and other major Chinese consumer platforms, making IP-layer blocking operationally costly.
##One Certificate, Nineteen Payloads: How a Wubi IME Trojan Hides Behind a Valid DigiCert Signature and China's Largest CDN Nineteen Windows executables — all masquerading as the 万能五笔输入法 (WanNeng Wubi IME) Chinese input-method suite and all carrying a single valid DigiCert code-signing certificate issued to Shanghai Oriental Webcasting Co. Ltd.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read