
One DigiCert Chain, Three Chengdu Shells, 12 Signed Adware Installers
Eighteen months of Windows installer stubs — cleaners, ad blockers, 'optimizer' tools — all chain up through the same DigiCert Trusted G4 Code Signing intermediate while the leaf signer identity rotates across three different Chengdu-registered companies. Static AV still flags a third of engines, but sandboxes report every signed sample clean.
A rotating cast of Chengdu-registered shell companies has spent the past eighteen months feeding disposable code-signing identities into a single DigiCert trust chain, and the resulting installers are still walking past static AV and sandbox alike. Twelve Windows binaries examined here — installer stubs for C-drive cleaners, ad blockers, and "system optimizer" tools bundled under LuDaShi/SuperApp-style directory trees — all chain up through the same DigiCert Trusted G4 Code Signing RSA4096…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read