
Six Shell Companies, One Builder: DigiCert Certs Fuelled 14-Month Signed-Malware Run
Thirty-four Windows executables carrying valid DigiCert code-signing certificates — each issued to a distinct Chinese company — have circulated since October 2024 disguised as consumer PC utilities. A single operator burned through six shell-company identities while routing command-and-control through Alibaba and Tencent CDN fronts, escalating from adware-class collection to WMI-based host enumeration.
Thirty-four Windows executables carrying valid DigiCert Trusted G4 Code Signing certificates — each issued to a distinct Chinese company identity — have been circulating since October 2024, disguised as consumer PC-utility software: file cleaners, memory optimisers, browser protectors, and QQ-related tray applications. The signing identities rotate. The build toolchain does not.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read