APTMembers
APT

Four Shell Companies, One CA: How Ludashi Buries Payloads in Trusted Certs

A campaign attributed to Patchwork rotates code-signing certificates across four Chinese shell companies — all rooted in a single DigiCert intermediate CA — to keep trojanized consumer software lures trusted across a ten-month payload timeline. The operator pre-staged ten C2 subdomains via Alibaba HiChina thirteen months before activating them, routing payload delivery through legitimate Alibaba CDN infrastructure to blend with normal Chinese internet traffic.

May 29, 2026, 17:53 (UTC+9)Last seenMay 29, 2026Severity100ByCTX TeamActorPatchworkChinastratsIOC90MITRE18

Seventeen Windows executables and DLLs. Four distinct Chinese corporate identities. A single DigiCert intermediate certificate authority threading through all of them. That is the structural core of a Ludashi adware and trojan campaign that CTX Team has been tracking across a ten-month payload timeline stretching from July 2025 through late May 2026 — a campaign that uses rotating shell-company code-signing certificates, deliberate PE header corruption, and a pre-staged CDN infrastructure built…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence