
Dual DigiCert Certs Keep Ludashi Adware Invisible for 15 Months
Sixteen signed PE32 payloads distributed under Chinese PC-optimization brands have evaded sandbox detection for fifteen months by exploiting valid, unrevoked DigiCert code-signing certificates issued to two separate Chinese companies. The campaign's dual-certificate architecture, CDN-fronted C2 cluster, and active IR-tool enumeration mark it as a deliberately maintained distribution infrastructure rather than opportunistic adware.
Sixteen Windows executables carrying valid, unrevoked DigiCert code-signing certificates issued to two distinct Chinese companies have been circulating as trojanized PC-optimization installers across a fifteen-month window — a sustained signed-binary abuse campaign that returns a clean verdict from every sandbox that examines it, even as detection ratios on the same files reach as high as 38 of 77 engines on VirusTotal.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read