C&CMembers
C&C

One DigiCert Root, Four Shell Firms: Inside a Chinese Adware Signing Ring

A single DigiCert code-signing root has backed twenty Chinese PC-optimizer installers for three years under four different, rotating signer identities. The certificates stay valid even as most of the binaries they sign are flagged by dozens of antivirus engines as Ludashi/Chinad/PolarWind adware.

Jul 12, 2026, 05:45 (UTC+9)Last seenJul 12, 2026Severity100ByCTX TeamActorPatchworkChinastratsIOC68

A single DigiCert code-signing root has quietly underwritten twenty different Chinese PC-optimizer and "app store" installers over roughly three years — but the signer name attached to that root has changed four times. 成都奇鲁科技有限公司, 北京创想界科技有限公司, 成都星汉云科科技有限公司, and a now-expired Chengdu Qilu Technology Co. Ltd. certificate all chain up to either "DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1" or its SHA2 predecessor, signing installer chrome, uninstallers, and helper DLLs that…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence