APTMembers
APT

Salty Spider Hides RAT in Signed Bundles via Two DigiCert Certs

Twenty malicious Windows files have circulated for fifteen months under valid DigiCert G4 code-signing certificates issued to two Chinese front companies. The campaign embeds a PubNubRAT remote-access capability inside signed DLLs while masquerading as a routine Chinese system-utility suite, with a layered evasion stack that has kept most samples below 20 antivirus detections.

May 24, 2026, 14:01 (UTC+9)Last seenMay 24, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC51MITRE14

Twenty malicious Windows executables and DLLs have been circulating under valid DigiCert G4 code-signing certificates issued to two Chinese-registered front entities — a dual-certificate architecture that has remained unrotated across a fifteen-month active build window while the operator quietly embedded a PubNubRAT remote-access capability inside what presents to users as a routine system-utility bundle.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence