
Salty Spider Turns Revoked Certificates Into a 71/76 Evasion Tool
Two Windows executables signed with an explicitly revoked Certum certificate cleared 71 of 76 scanning engines on 23 May 2026. The files are the latest output of a ten-month campaign in which at least five Chinese-registered entities cycled through DigiCert G4 code-signing certificates to deploy the Sality/Ludashi adware-trojan family. The operation reveals a systematic, industrialised pipeline for signed-binary evasion rather than opportunistic adware distribution.
Two Windows executables submitted to public malware repositories on 23 May 2026 — both signed with a code-signing certificate that had already been revoked by its issuing CA — cleared 71 of 76 scanning engines without triggering a single alert. The files, bearing the product description "Pro解压缩" (Pro Decompression) and the internal name uninst.exe, were the freshest output of a campaign that CTX Team has been tracking across a ten-month arc stretching from July 2025 to the present.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read