C&CMembers
C&C

Four Corporate Fronts, One Build Pipeline: 18-Month DigiCert Signing Spree

A single operator has obtained DigiCert G4 code-signing certificates under four distinct Chinese corporate identities and rotated them across a shared build pipeline to deliver adware, trojans, and remote access tooling through consumer software bundles. PE overlay abuse and active sandbox suppression have kept the campaign's detection profile in the gap between static and dynamic analysis pipelines for over eighteen months. The operation's three active certificates collectively provide signing runway through mid-2027 without requiring any new identity acquisition.

Jun 1, 2026, 00:45 (UTC+9)Last seenJun 1, 2026Severity82ByCTX TeamIOC96MITRE25

Fifteen signed Windows executables. Four registered Chinese companies. One DigiCert certificate authority chain threading through all of them. The campaign CTX Team has been tracking across an 18-month window does not rely on a single forged credential or a stolen certificate — it relies on something more durable: a systematic program of acquiring legitimate DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 certificates under distinct corporate identities, then rotating those identities…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence