
Salty Spider Hides RAT in Signed Bundles via Two DigiCert Certs
Twenty malicious Windows files have circulated for fifteen months under valid DigiCert G4 code-signing certificates issued to two Chinese front companies. The campaign embeds a PubNubRAT remote-access capability inside signed DLLs while masquerading as a routine Chinese system-utility suite, with a layered evasion stack that has kept most samples below 20 antivirus detections.
Twenty malicious Windows executables and DLLs have been circulating under valid DigiCert G4 code-signing certificates issued to two Chinese-registered front entities — a dual-certificate architecture that has remained unrotated across a fifteen-month active build window while the operator quietly embedded a PubNubRAT remote-access capability inside what presents to users as a routine system-utility bundle.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read