
Ludashi Campaign Adds Second Code-Signing Cert to Survive Revocation
The Ludashi adware and trojan campaign has quietly obtained a second DigiCert code-signing certificate under a structurally independent Chengdu-registered company, held in reserve for three months before deployment. The move creates a two-certificate architecture explicitly designed so that revoking the primary certificate leaves the secondary entirely intact, extending the campaign's evasion runway across a payload stack now confirmed at 19 signed binaries.
##A Second Certificate, A Second Company: How the Ludashi Campaign Hardened Its Signing Infrastructure Since CTX Team's earlier coverage of the Ludashi adware and trojan campaign, twelve new file indicators, seven new IP addresses, and a new payload-delivery URL have surfaced — but the most operationally significant development is not the volume expansion.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read