C&CMembers
C&C

Fake Browser Installers Use Valid EV Certificates to Spread Adware

Two Windows installers impersonating GptChrome and JiSu browsers carry fully valid EV code-signing certificates issued to newly-registered Chinese companies, yet both are flagged by 30+ security engines as trojan/adware droppers. The mismatch shows operators investing in shell-company paperwork to pass CA identity checks rather than binary obfuscation.

Jul 23, 2026, 21:42 (UTC+9)Last seenJul 23, 2026Severity82ByCTX TeamActorAPT28StrontiumIOC12MITRE13

A pair of Windows installers now flagged by 30 or more security engines each didn't need packers, obfuscated loaders, or stolen certificates to get past baseline defenses — they used real ones, freshly issued to real, if newly registered, Chinese companies. One installer poses as "GptChrome," a knockoff AI-browser setup; the other impersonates JiSu (极速浏览器), a popular Chinese browser installer.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence