APTMembers
APT

Three Shell Companies, One Pipeline: Chinese Signing Op Delivers PubNubRAT

At least three Chinese-registered legal entities have independently obtained valid DigiCert G4 code-signing certificates to distribute Ludashi/Chinad adware-trojan hybrids and PubNubRAT implants. The operation treats certificate procurement as a repeatable supply-chain function, rotating signing identities before expiry and staging delivery infrastructure months in advance to sustain trust-chain bypass at scale.

Jun 6, 2026, 11:07 (UTC+9)Last seenJun 6, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC49MITRE18

Sixteen malicious Windows executables and DLLs are currently circulating under valid DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 certificates — each certificate issued to a distinct Chinese-registered legal entity, each carrying a three-year validity window, and each actively suppressing the dynamic analysis environments that defenders rely on to catch what static signatures miss. The operation is not a single rogue certificate.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence