
Ludashi Adware Ring Abused DigiCert Certs Across Five Shell Firms
A factory-style adware operation obtained valid DigiCert G4 code-signing certificates under at least five separately registered Chinese companies to sign a continuous stream of Ludashi-family payloads. Overlay-based hash mutation and Tencent Cloud delivery infrastructure compounded the evasion, while a revoked-certificate binary achieved just one detection out of 70 engines.
Fifteen signed Windows executables. Five distinct Chinese company identities. One commercial certificate authority. A single cert serial binding nine of those payloads to a three-year production window that is still running. The operation CTX Team has been tracking targets the telecom sector and exploits a structural weakness that most enterprise endpoint stacks have not solved: when a binary carries a valid, trusted code-signing certificate, a significant fraction of the detection stack simply…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read