C&CMembers
C&C

One DigiCert Certificate, 17 Malicious Payloads, Three-Year Signing Window

A Chinese shell entity obtained a legitimate DigiCert G4 code-signing certificate and used it to sign an entire campaign toolkit across eight months of active development. The operator combined valid signing, active sandbox evasion, and a PubNub cloud-messaging RAT channel to build a system designed to survive every standard detection layer simultaneously.

Jun 6, 2026, 23:59 (UTC+9)Last seenJun 6, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC107MITRE26

In September 2024, someone registered a code-signing certificate with DigiCert under the name of a Beijing technology company — 北京创想界科技有限公司 — and within six weeks began using it to sign malicious software. By the time CTX Team catalogued the full file cohort, that single certificate, serial number 06 FE 57 2B A6 2E 8E C3 18 03 0F DC 9B AC A2 81, had been applied to 17 distinct PE32 executables and DLLs spanning two trojanized utility brands, a modular plugin architecture, and at least one…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence