
Two DigiCert Certificates, 16 Malicious Binaries, Nine Months Unrevoked
A campaign tracked to TA511 has circulated 16 signed Windows executables through Chinese-language software channels since August 2025, all bearing valid DigiCert G4 certificates issued to two Chengdu shell companies. A deliberate dual-certificate architecture and progressive evasion hardening — including a UPX-packed variant hitting only 7/76 detections — have kept the operation running while neither certificate has been revoked.
Sixteen Windows executables bearing currently-valid DigiCert G4 code-signing certificates have been circulating across Chinese-language software distribution channels since at least August 2025, impersonating disk-cleaners, QQ-cleanup utilities, zip tools, and browser-guard products — a signed-binary abuse chain [T1553.002] that walks past Windows SmartScreen and suppresses the heuristic engines that most enterprise endpoints rely on.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read