APTMembers
APT

Salty Spider Turns Revoked Certificates Into a 71/76 Evasion Tool

Two Windows executables signed with an explicitly revoked Certum certificate cleared 71 of 76 scanning engines on 23 May 2026. The files are the latest output of a ten-month campaign in which at least five Chinese-registered entities cycled through DigiCert G4 code-signing certificates to deploy the Sality/Ludashi adware-trojan family. The operation reveals a systematic, industrialised pipeline for signed-binary evasion rather than opportunistic adware distribution.

May 26, 2026, 22:03 (UTC+9)Last seenMay 26, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC27MITRE42

Two Windows executables submitted to public malware repositories on 23 May 2026 — both signed with a code-signing certificate that had already been revoked by its issuing CA — cleared 71 of 76 scanning engines without triggering a single alert. The files, bearing the product description "Pro解压缩" (Pro Decompression) and the internal name uninst.exe, were the freshest output of a campaign that CTX Team has been tracking across a ten-month arc stretching from July 2025 to the present.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence