APTMembers
APT

Valid DigiCert Cert Turns 2345 SafeCenter Update Channel Into Malware Pipeline

Seventeen Windows PE files posing as 2345 SafeCenter and HaoZip components carry a still-valid DigiCert code-signing certificate that suppresses SmartScreen warnings and fools automated sandboxes. One component matches an ESET YARA rule for SQL Server authentication bypass, raising the threat classification well above commodity adware. The campaign was still signing new builds as of 2026-05-29.

May 31, 2026, 19:32 (UTC+9)Last seenMay 31, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC61MITRE8

Seventeen Windows PE files masquerading as components of the 2345 SafeCenter security suite and HaoZip archiver are circulating with a currently-valid DigiCert code-signing certificate issued to Shanghai 2345 Mobile Technology Co., Ltd. — a credential that suppresses Windows SmartScreen warnings and causes automated sandbox platforms to return clean verdicts on samples that 25 to 38 static antivirus engines simultaneously flag as adware.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence