APTMembers
APT

Fake PDF Reader Ecosystem Runs on Two Valid Corporate Code Signatures

Eighteen consumer-utility installers — PDF readers, zip tools, photo viewers — are being signed under two separate, still-valid commercial certificate chains: a GlobalSign cert issued to a Cangzhou firm covering 13 files, and a DigiCert cert issued to a Chengdu firm covering 3. Dozens of AV engines flag the files as adware while sandboxes largely pass them as clean.

Sep 7, 2026, 22:29 (UTC+9)Last seenSep 7, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC23MITRE10

Two entirely separate, still-valid commercial code-signing chains are being used in parallel to push the same lure: consumer utility installers — PDF readers, zip tools, photo viewers — that dozens of antivirus engines flag as adware while sandboxes wave them through as clean. Thirteen samples carry a GlobalSign GCC R45 CodeSigning CA 2020 certificate issued to 沧州句号网络科技有限公司 (Cangzhou Juhao Network Technology Co., Ltd.), with detection ratios ranging from 18 to 46 out of roughly 77 engines.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence