APTMembers
APT

Five-Year Cert Rotation Engine Keeps Chinese-Ecosystem Malware Signed

A campaign active since at least 2021 has maintained sustained access to DigiCert G4 code-signing infrastructure through six distinct Chinese-registered legal entities, rotating leaf certificates to reset AV detection clocks while a single trusted intermediate CA anchor persists through 2036. Trojanized installers impersonating MultiWeChat, TabX Explorer, Ludashi utilities, and WPS Office components deliver adware payloads, with command-and-control traffic routed through Alibaba Kunlun CDN to mimic legitimate Chinese software update behavior. Upstream attribution to APT28 sits in direct tension with technical evidence pointing uniformly toward the Chinese-language software ecosystem.

Jun 1, 2026, 20:47 (UTC+9)Last seenJun 2, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC22MITRE10

Nine Windows executables and DLLs masquerading as MultiWeChat, TabX Explorer, Ludashi system utilities, and WPS Office components have been circulating with valid DigiCert code-signing certificates — not because a single company's identity was stolen, but because whoever operates this campaign has maintained sustained access to DigiCert's G4 code-signing infrastructure through six distinct Chinese-registered legal entities across a span of nearly five years.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence