
Five-Year Cert Rotation Engine Keeps Chinese-Ecosystem Malware Signed
A campaign active since at least 2021 has maintained sustained access to DigiCert G4 code-signing infrastructure through six distinct Chinese-registered legal entities, rotating leaf certificates to reset AV detection clocks while a single trusted intermediate CA anchor persists through 2036. Trojanized installers impersonating MultiWeChat, TabX Explorer, Ludashi utilities, and WPS Office components deliver adware payloads, with command-and-control traffic routed through Alibaba Kunlun CDN to mimic legitimate Chinese software update behavior. Upstream attribution to APT28 sits in direct tension with technical evidence pointing uniformly toward the Chinese-language software ecosystem.
Nine Windows executables and DLLs masquerading as MultiWeChat, TabX Explorer, Ludashi system utilities, and WPS Office components have been circulating with valid DigiCert code-signing certificates — not because a single company's identity was stolen, but because whoever operates this campaign has maintained sustained access to DigiCert's G4 code-signing infrastructure through six distinct Chinese-registered legal entities across a span of nearly five years.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read