C&CMembers
C&C

Ludashi Campaign Adds Second Code-Signing Cert to Survive Revocation

The Ludashi adware and trojan campaign has quietly obtained a second DigiCert code-signing certificate under a structurally independent Chengdu-registered company, held in reserve for three months before deployment. The move creates a two-certificate architecture explicitly designed so that revoking the primary certificate leaves the secondary entirely intact, extending the campaign's evasion runway across a payload stack now confirmed at 19 signed binaries.

Jun 8, 2026, 07:30 (UTC+9)Last seenJun 8, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC52MITRE13

##A Second Certificate, A Second Company: How the Ludashi Campaign Hardened Its Signing Infrastructure Since CTX Team's earlier coverage of the Ludashi adware and trojan campaign, twelve new file indicators, seven new IP addresses, and a new payload-delivery URL have surfaced — but the most operationally significant development is not the volume expansion.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence