APTMembers
APT

Ludashi Adware Ring Abused DigiCert Certs Across Five Shell Firms

A factory-style adware operation obtained valid DigiCert G4 code-signing certificates under at least five separately registered Chinese companies to sign a continuous stream of Ludashi-family payloads. Overlay-based hash mutation and Tencent Cloud delivery infrastructure compounded the evasion, while a revoked-certificate binary achieved just one detection out of 70 engines.

Jun 6, 2026, 23:10 (UTC+9)Last seenJun 7, 2026Severity100ByCTX TeamActorGorgon GroupSubaatIOC55MITRE10

Fifteen signed Windows executables. Five distinct Chinese company identities. One commercial certificate authority. A single cert serial binding nine of those payloads to a three-year production window that is still running. The operation CTX Team has been tracking targets the telecom sector and exploits a structural weakness that most enterprise endpoint stacks have not solved: when a binary carries a valid, trusted code-signing certificate, a significant fraction of the detection stack simply…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence