FILEMembers
FILE

One Certificate Signs Launcher, App, and Repair Tool in 3 Minutes

A single DigiCert-issued certificate to SPRING (SG) PTE. LTD signs a Dola/Cici launcher, main application, and repair utility within a three-minute window, yielding near-zero detection across security engines. Four Brazil-hosted IPs sharing an identical TLS certificate serial behind a *.certfallback.com front add a second durable infrastructure fingerprint.

Aug 9, 2026, 11:05 (UTC+9)Last seenAug 9, 2026Severity66ByCTX TeamActorAPT28StrontiumIOC11MITRE38

A single code-signing certificate — issued to SPRING (SG) PTE. LTD through the DigiCert Trusted G4 Code Signing chain — covers three functionally distinct Windows binaries: a launcher, an installed application, and a self-repair utility, all signed between 06:04 and 06:07 AM on August 2, 2026. That three-minute spread across three separate files is the most concrete fact in this record, and it reads less like three developers reaching for the same certificate and more like one build pipeline…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence