
Fake PDF Reader Ecosystem Runs on Two Valid Corporate Code Signatures
Eighteen consumer-utility installers — PDF readers, zip tools, photo viewers — are being signed under two separate, still-valid commercial certificate chains: a GlobalSign cert issued to a Cangzhou firm covering 13 files, and a DigiCert cert issued to a Chengdu firm covering 3. Dozens of AV engines flag the files as adware while sandboxes largely pass them as clean.
Two entirely separate, still-valid commercial code-signing chains are being used in parallel to push the same lure: consumer utility installers — PDF readers, zip tools, photo viewers — that dozens of antivirus engines flag as adware while sandboxes wave them through as clean. Thirteen samples carry a GlobalSign GCC R45 CodeSigning CA 2020 certificate issued to 沧州句号网络科技有限公司 (Cangzhou Juhao Network Technology Co., Ltd.), with detection ratios ranging from 18 to 46 out of roughly 77 engines.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read