APTMembers
APT

One Unrevoked Certificate, 18 Builds: Inside a 14-Month Adware Campaign

A DigiCert code-signing certificate issued to a Chengdu technology company has anchored 18 trojanized Windows executables over 14 months — and remains valid through May 2027. CTX Team's latest sweep added 41 new file indicators and exposed a purpose-built C2 domain pair registered in December 2025 that carries a 0/91 detection ratio, confirming the operation is actively expanding.

May 29, 2026, 05:53 (UTC+9)Last seenMay 29, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC92MITRE13

A DigiCert code-signing certificate issued to a Chengdu technology company has been used continuously for more than 14 months to sign trojanized Windows executables masquerading as components of LuDaShi (鲁大师), one of China's most widely installed PC-optimization suites — and that certificate remains unrevoked today. CTX Team's latest sweep of the campaign has surfaced 41 new file indicators alongside a purpose-built command-and-control domain pair registered in December 2025 that carries a 0/91…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence