
Signed, Sealed, Trojanized: Dual Chengdu Certs Power RAT Campaign
Eighteen PE32 files impersonating Ludashi SuperApp utilities circulate with valid DigiCert code-signing certificates issued to two Chengdu entities, producing clean sandbox verdicts despite detection ratios reaching 34 of 76 engines. The campaign's critical escalation is a PubNubRAT-classified DLL — the only malicious sandbox verdict in the set — signaling a deliberate pivot from adware monetization to persistent remote-access capability within the same trusted signing infrastructure.
Eighteen Windows PE32 files — executables and DLLs impersonating Ludashi SuperApp system utilities — are circulating with currently-valid DigiCert Trusted G4 code-signing certificates issued to two Chengdu-registered entities, producing uniformly clean sandbox verdicts despite industry detection ratios that reach as high as 34 of 76 engines.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read