
Two Shell Firms, One DigiCert Root: Adware's Signing Trick Repeats
New adware installers AloneTrayServer.exe and MLPrivacy.exe carry valid certificates from a Chinese shell company that chains to the same DigiCert intermediate CA used by an earlier, differently named shell entity. The recurrence points to a reusable cert-broker or shell-rotation process built to survive AV scrutiny.
AloneTrayServer.exe and MLPrivacy.exe — two installers newly added to a long-running Chinese adware-distribution cluster — both carry valid, chained code-signing certificates issued to a company calling itself 成都星汉云科科技有限公司. That in itself would be unremarkable. What makes it worth a second look is that this is now the second shell identity CTX Team has traced back to the exact same intermediate certificate authority — DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 — after an earlier…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read