C&CMembers
C&C

Three Certs, One Chain: Signed Adware Campaign Evades Revocation for 8 Months

A China-nexus campaign distributing Ludashi and Chinad adware-trojan hybrids through trojanized Mandarin-language PC utilities has maintained continuous payload production since May 2025 by rotating DigiCert code-signing certificates across three distinct Chinese corporate identities. Revoking any single certificate serial leaves the other two intact under the same trusted intermediate CA chain. Every tested file returns a clean dynamic sandbox verdict despite static detection ratios reaching 39 of 76 engines.

Jun 6, 2026, 11:58 (UTC+9)Last seenJun 6, 2026Severity100ByCTX TeamActorTA551ShathakIOC56MITRE3

Seventeen signed Windows executables, three DigiCert code-signing certificates, three distinct Chinese corporate identities, and an eight-month continuous production window: what CTX Team has catalogued in this campaign is not a single malicious installer but an industrialised signing infrastructure engineered to survive the most common defensive response to signed malware — certificate revocation.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence