APTMembers
APT

Signed, Sealed, Trojanized: Dual Chengdu Certs Power RAT Campaign

Eighteen PE32 files impersonating Ludashi SuperApp utilities circulate with valid DigiCert code-signing certificates issued to two Chengdu entities, producing clean sandbox verdicts despite detection ratios reaching 34 of 76 engines. The campaign's critical escalation is a PubNubRAT-classified DLL — the only malicious sandbox verdict in the set — signaling a deliberate pivot from adware monetization to persistent remote-access capability within the same trusted signing infrastructure.

May 26, 2026, 23:45 (UTC+9)Last seenMay 26, 2026Severity100ByCTX TeamActorTurlaIron HunterIOC92MITRE16

Eighteen Windows PE32 files — executables and DLLs impersonating Ludashi SuperApp system utilities — are circulating with currently-valid DigiCert Trusted G4 code-signing certificates issued to two Chengdu-registered entities, producing uniformly clean sandbox verdicts despite industry detection ratios that reach as high as 34 of 76 engines.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence