C&CMembers
C&C

Dual DigiCert Certs Keep Ludashi Adware Invisible for 15 Months

Sixteen signed PE32 payloads distributed under Chinese PC-optimization brands have evaded sandbox detection for fifteen months by exploiting valid, unrevoked DigiCert code-signing certificates issued to two separate Chinese companies. The campaign's dual-certificate architecture, CDN-fronted C2 cluster, and active IR-tool enumeration mark it as a deliberately maintained distribution infrastructure rather than opportunistic adware.

May 31, 2026, 08:55 (UTC+9)Last seenMay 31, 2026Severity100ByCTX TeamActorTA551ShathakIOC62MITRE6

Sixteen Windows executables carrying valid, unrevoked DigiCert code-signing certificates issued to two distinct Chinese companies have been circulating as trojanized PC-optimization installers across a fifteen-month window — a sustained signed-binary abuse campaign that returns a clean verdict from every sandbox that examines it, even as detection ratios on the same files reach as high as 38 of 77 engines on VirusTotal.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence