C&CMembers
C&C

Signed Adware Toolkit Targets Telecom With Two Live DigiCert Certs

Seventeen Windows binaries spanning crash reporters, plugin managers, and a suspected remote-access trojan circulate under valid DigiCert G4 code-signing certificates issued to two Chinese firms, both valid until 2027. The toolkit pairs PUA utility software delivery with a structured HTTPS monetisation and C2 backend at dllfix.cn and tjbxldkj.cn, and systematically evades sandbox analysis across fourteen of eighteen components.

Jun 7, 2026, 19:58 (UTC+9)Last seenJun 7, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC90MITRE20

Seventeen Windows executables and DLLs — spanning crash reporters, plugin managers, system tray utilities, and at least one component that a sandbox flagged as a remote-access trojan — are circulating under currently valid DigiCert Trusted G4 code-signing certificates issued to two Chinese corporate entities, with both certificates remaining valid until 2027.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence