C&CMembers
C&C

Six Shell Companies, One Builder: DigiCert Certs Fuelled 14-Month Signed-Malware Run

Thirty-four Windows executables carrying valid DigiCert code-signing certificates — each issued to a distinct Chinese company — have circulated since October 2024 disguised as consumer PC utilities. A single operator burned through six shell-company identities while routing command-and-control through Alibaba and Tencent CDN fronts, escalating from adware-class collection to WMI-based host enumeration.

May 24, 2026, 17:57 (UTC+9)Last seenMay 24, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC68MITRE23

Thirty-four Windows executables carrying valid DigiCert Trusted G4 Code Signing certificates — each issued to a distinct Chinese company identity — have been circulating since October 2024, disguised as consumer PC-utility software: file cleaners, memory optimisers, browser protectors, and QQ-related tray applications. The signing identities rotate. The build toolchain does not.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence