
Three Certs, One Chain: Signed Adware Campaign Evades Revocation for 8 Months
A China-nexus campaign distributing Ludashi and Chinad adware-trojan hybrids through trojanized Mandarin-language PC utilities has maintained continuous payload production since May 2025 by rotating DigiCert code-signing certificates across three distinct Chinese corporate identities. Revoking any single certificate serial leaves the other two intact under the same trusted intermediate CA chain. Every tested file returns a clean dynamic sandbox verdict despite static detection ratios reaching 39 of 76 engines.
Seventeen signed Windows executables, three DigiCert code-signing certificates, three distinct Chinese corporate identities, and an eight-month continuous production window: what CTX Team has catalogued in this campaign is not a single malicious installer but an industrialised signing infrastructure engineered to survive the most common defensive response to signed malware — certificate revocation.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read