
One DigiCert Certificate, 14 Malicious Binaries, 18 Months Unrevoked
A single code-signing certificate issued to a Chinese entity has authenticated 14 distinct malicious Windows binaries across at least six consumer PC-utility brands over 18 months without ever being revoked. The operator pre-positioned the certificate six months before first deployment, built a ten-brand rebranding factory on a shared 'SuperApp' scaffold, and routed command-and-control traffic through Tencent API Gateway to frustrate network-layer blocking.
A single unrevoked DigiCert code-signing certificate — issued to the Chinese entity 成都奇鲁科技有限公司 and carrying serial number 0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98, valid from May 21, 2024 through May 20, 2027 — has been used to sign 14 distinct malicious Windows binaries deployed across at least six consumer-facing product brands over an 18-month window.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read