
Three Chinese Shell Firms, One DigiCert Chain, and a Kernel Driver in an Adware Campaign
A 14-month signing operation tied to Salty Spider has produced at least eleven validly signed Windows PE files across three distinct Chinese corporate entities, all sharing a single DigiCert G4 intermediate CA. The campaign bundles a LOLDrivers-listed vulnerable kernel driver alongside lock-screen adware, routes command-and-control through Alibaba KunLun CDN, and is already building a fallback Certum signing channel against anticipated revocation.
Fourteen months of continuous payload production. Eleven distinct PE files — DLLs and installer EXEs alike — all bearing the same unrevoked leaf certificate issued to a single Beijing-registered technology company. A second Chinese entity in Chengdu holding its own valid DigiCert credential, and a third Chengdu firm with a third.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read