
Four Shell Companies, One CA: How Ludashi Buries Payloads in Trusted Certs
A campaign attributed to Patchwork rotates code-signing certificates across four Chinese shell companies — all rooted in a single DigiCert intermediate CA — to keep trojanized consumer software lures trusted across a ten-month payload timeline. The operator pre-staged ten C2 subdomains via Alibaba HiChina thirteen months before activating them, routing payload delivery through legitimate Alibaba CDN infrastructure to blend with normal Chinese internet traffic.
Seventeen Windows executables and DLLs. Four distinct Chinese corporate identities. A single DigiCert intermediate certificate authority threading through all of them. That is the structural core of a Ludashi adware and trojan campaign that CTX Team has been tracking across a ten-month payload timeline stretching from July 2025 through late May 2026 — a campaign that uses rotating shell-company code-signing certificates, deliberate PE header corruption, and a pre-staged CDN infrastructure built…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read