
Three Shell Companies, One Pipeline: Chinese Signing Op Delivers PubNubRAT
At least three Chinese-registered legal entities have independently obtained valid DigiCert G4 code-signing certificates to distribute Ludashi/Chinad adware-trojan hybrids and PubNubRAT implants. The operation treats certificate procurement as a repeatable supply-chain function, rotating signing identities before expiry and staging delivery infrastructure months in advance to sustain trust-chain bypass at scale.
Sixteen malicious Windows executables and DLLs are currently circulating under valid DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 certificates — each certificate issued to a distinct Chinese-registered legal entity, each carrying a three-year validity window, and each actively suppressing the dynamic analysis environments that defenders rely on to catch what static signatures miss. The operation is not a single rogue certificate.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read