
One Unrevoked Certificate, 18 Builds: Inside a 14-Month Adware Campaign
A DigiCert code-signing certificate issued to a Chengdu technology company has anchored 18 trojanized Windows executables over 14 months — and remains valid through May 2027. CTX Team's latest sweep added 41 new file indicators and exposed a purpose-built C2 domain pair registered in December 2025 that carries a 0/91 detection ratio, confirming the operation is actively expanding.
A DigiCert code-signing certificate issued to a Chengdu technology company has been used continuously for more than 14 months to sign trojanized Windows executables masquerading as components of LuDaShi (鲁大师), one of China's most widely installed PC-optimization suites — and that certificate remains unrevoked today. CTX Team's latest sweep of the campaign has surfaced 41 new file indicators alongside a purpose-built command-and-control domain pair registered in December 2025 that carries a 0/91…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read