
Salty Spider Abuses Live DigiCert Cert for 17 Months of Malicious Builds
Seven Windows binaries across two 2345 Software product lines share a single, still-valid DigiCert code-signing certificate that the operator kept applying to fresh malicious builds through April 2026. All delivery and C2 traffic routes through Alibaba CDN infrastructure, making the campaign functionally invisible at both the file-trust and network-traffic layers in isolation.
Seven Windows executables and DLLs flagged as adware — spanning two distinct 2345 Software product lines — carry an identical, currently-valid DigiCert code-signing certificate issued to Shanghai 2345 Mobile Technology Co., Ltd., and the operator was still applying that same credential to fresh malicious builds as recently as April 7, 2026.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read