
Batch-Signed Adware Beats AV Detection, Fools Every Sandbox
Two Chinese-issued code-signing certificates were used to mass-sign near-identical GoodZip and WanNengWBInput installer components within minutes of each other, producing files that draw 27-51 AV detections yet return a clean verdict from every sandbox that ran them. Feed metadata tags the record APT27 and Salty Spider, but nothing in the signing, build, or behavioral data matches either group's known tradecraft.
A code-signing certificate issued to a company called Shenzhen Kaixin Kangaroo Technology Co., Ltd. was used to sign eight different executables and DLLs — all in the same eight-minute window on March 20, 2024. A separate certificate, issued this time to Shanghai Oriental Webcasting Co. Ltd., produced the same pattern two months later: seven of eight files signed within a single minute on May 29, 2024.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read