
Signed Adware Toolkit Targets Telecom With Two Live DigiCert Certs
Seventeen Windows binaries spanning crash reporters, plugin managers, and a suspected remote-access trojan circulate under valid DigiCert G4 code-signing certificates issued to two Chinese firms, both valid until 2027. The toolkit pairs PUA utility software delivery with a structured HTTPS monetisation and C2 backend at dllfix.cn and tjbxldkj.cn, and systematically evades sandbox analysis across fourteen of eighteen components.
Seventeen Windows executables and DLLs — spanning crash reporters, plugin managers, system tray utilities, and at least one component that a sandbox flagged as a remote-access trojan — are circulating under currently valid DigiCert Trusted G4 code-signing certificates issued to two Chinese corporate entities, with both certificates remaining valid until 2027.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read