C&CMembers
C&C

Two Shell Firms, One DigiCert Root: Adware's Signing Trick Repeats

New adware installers AloneTrayServer.exe and MLPrivacy.exe carry valid certificates from a Chinese shell company that chains to the same DigiCert intermediate CA used by an earlier, differently named shell entity. The recurrence points to a reusable cert-broker or shell-rotation process built to survive AV scrutiny.

Sep 21, 2026, 22:29 (UTC+9)Last seenSep 21, 2026Severity100ByCTX TeamIOC17MITRE45

AloneTrayServer.exe and MLPrivacy.exe — two installers newly added to a long-running Chinese adware-distribution cluster — both carry valid, chained code-signing certificates issued to a company calling itself 成都星汉云科科技有限公司. That in itself would be unremarkable. What makes it worth a second look is that this is now the second shell identity CTX Team has traced back to the exact same intermediate certificate authority — DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 — after an earlier…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence