
C&CMembers
C&COne Chinese Signing Cert Underwrites Nine Adware Payloads
A single code-signing identity tied to 沧州句号网络科技有限公司 has stamped nine Windows adware installers split across two 'utility' brands, GoodZip-WIN助手 and 开心看图王-WIN助手. Detection ratios run 32-46/77 on VirusTotal, yet sandbox runs consistently come back clean.
Jul 28, 2026, 13:43 (UTC+9)Last seenJul 28, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC19MITRE11
A single Chinese code-signing identity has quietly underwritten an entire adware production line. Nine distinct Windows binaries — a mix of EXEs and DLLs distributed under two different "utility" brand names — all carry the identical certificate chain: 沧州句号网络科技有限公司, chained through GlobalSign GCC R45 CodeSigning CA 2020, GlobalSign Code Signing Root R45, and GlobalSign Root CA - R3.
Members only
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to readSource: CTX Threat Intelligence