
Signed Chinese Input-Method Suite Hides IcedID-Flagged Loader
Four EV-signed binaries branded as a popular Chinese Wubi input method share one build batch and, in two cases, a static IcedID payload signature — despite clean sandbox verdicts. The cluster extends to signed kernel drivers and CDN-impersonating IPs, with medium-confidence ties to APT27.
Four Windows binaries branded as 万能五笔输入法 — a legitimate Chinese Wubi input-method suite — carry an identical Extended Validation code-signing certificate, the same build timestamp, and, in two cases, a payload signature tied to the IcedID malware family, even though the sandboxes that examined them returned a clean verdict. The pairing of trusted EV signing with a static loader-kit fingerprint that slips past dynamic analysis is the sharpest signal in a nine-file, nine-IP cluster CTX Team has…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read