
One GlobalSign Certificate Anchors 20 Malicious Files in Chinese Utility Trojan Campaign
A GlobalSign code-signing certificate issued to a Chinese entity underpins at least 20 malicious Windows binaries across two build waves in 2025. The campaign disguises credential-harvesting payloads as Chinese-language utility software while routing delivery through Wangsu CDN infrastructure that defeats IP-layer blocking. Systematic sandbox evasion leaves static detection as the only reliable defensive signal.
A GlobalSign code-signing certificate issued to the Chinese entity 沧州句号网络科技有限公司 (Cangzhou Juhao Network Technology Co., Ltd.) has served as the operational backbone for at least 20 malicious Windows executables and DLLs spanning two distinct build waves — one in May 2025 and a second in September 2025 — all delivered through a Wangsu (ChinaNetCenter) CDN-fronted infrastructure that renders conventional IP-layer blocking effectively useless.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read