C&CMembers
C&C

One DigiCert Chain, Three Chengdu Shells, 12 Signed Adware Installers

Eighteen months of Windows installer stubs — cleaners, ad blockers, 'optimizer' tools — all chain up through the same DigiCert Trusted G4 Code Signing intermediate while the leaf signer identity rotates across three different Chengdu-registered companies. Static AV still flags a third of engines, but sandboxes report every signed sample clean.

Aug 11, 2026, 06:38 (UTC+9)Last seenAug 11, 2026Severity100ByCTX TeamActorAPT29MinidionisIOC25MITRE26

A rotating cast of Chengdu-registered shell companies has spent the past eighteen months feeding disposable code-signing identities into a single DigiCert trust chain, and the resulting installers are still walking past static AV and sandbox alike. Twelve Windows binaries examined here — installer stubs for C-drive cleaners, ad blockers, and "system optimizer" tools bundled under LuDaShi/SuperApp-style directory trees — all chain up through the same DigiCert Trusted G4 Code Signing RSA4096…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence