APTMembers
APT

Three Chinese Shell Firms, One DigiCert Chain, and a Kernel Driver in an Adware Campaign

A 14-month signing operation tied to Salty Spider has produced at least eleven validly signed Windows PE files across three distinct Chinese corporate entities, all sharing a single DigiCert G4 intermediate CA. The campaign bundles a LOLDrivers-listed vulnerable kernel driver alongside lock-screen adware, routes command-and-control through Alibaba KunLun CDN, and is already building a fallback Certum signing channel against anticipated revocation.

Jun 5, 2026, 07:37 (UTC+9)Last seenJun 5, 2026Severity82ByCTX TeamActorSalty SpiderKuKuIOC55MITRE32

Fourteen months of continuous payload production. Eleven distinct PE files — DLLs and installer EXEs alike — all bearing the same unrevoked leaf certificate issued to a single Beijing-registered technology company. A second Chinese entity in Chengdu holding its own valid DigiCert credential, and a third Chengdu firm with a third.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence