
One Certificate Signs Launcher, App, and Repair Tool in 3 Minutes
A single DigiCert-issued certificate to SPRING (SG) PTE. LTD signs a Dola/Cici launcher, main application, and repair utility within a three-minute window, yielding near-zero detection across security engines. Four Brazil-hosted IPs sharing an identical TLS certificate serial behind a *.certfallback.com front add a second durable infrastructure fingerprint.
A single code-signing certificate — issued to SPRING (SG) PTE. LTD through the DigiCert Trusted G4 Code Signing chain — covers three functionally distinct Windows binaries: a launcher, an installed application, and a self-repair utility, all signed between 06:04 and 06:07 AM on August 2, 2026. That three-minute spread across three separate files is the most concrete fact in this record, and it reads less like three developers reaching for the same certificate and more like one build pipeline…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read