APTMembers
APT

Void Arachne Splits DigiCert Abuse Across Three Firms to Outrun Revocation

Eight trojanised Windows executables disguised as disk cleaners and Android emulator components carry valid DigiCert G4 signatures obtained under three distinct Chinese legal entities. The fragmentation strategy ensures revocation of any single certificate leaves the rest of the toolset intact, while a shared packing toolchain quietly binds all three clusters to a common build pipeline.

May 31, 2026, 23:52 (UTC+9)Last seenMay 31, 2026Severity90ByCTX TeamActorVoid ArachneSilver FoxIOC22MITRE4

Eight PE32 executables dressed as consumer disk cleaners and Android emulator components are circulating with valid DigiCert G4 code-signing certificates obtained under three distinct Chinese legal entities — a deliberate identity-fragmentation strategy that keeps each certificate clean while a shared packing toolchain quietly links the clusters behind the scenes.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence