C&CMembers
C&C

Two DigiCert Certificates, 16 Malicious Binaries, Nine Months Unrevoked

A campaign tracked to TA511 has circulated 16 signed Windows executables through Chinese-language software channels since August 2025, all bearing valid DigiCert G4 certificates issued to two Chengdu shell companies. A deliberate dual-certificate architecture and progressive evasion hardening — including a UPX-packed variant hitting only 7/76 detections — have kept the operation running while neither certificate has been revoked.

May 26, 2026, 10:27 (UTC+9)Last seenMay 26, 2026Severity100ByCTX TeamActorTA511MAN1IOC40MITRE4

Sixteen Windows executables bearing currently-valid DigiCert G4 code-signing certificates have been circulating across Chinese-language software distribution channels since at least August 2025, impersonating disk-cleaners, QQ-cleanup utilities, zip tools, and browser-guard products — a signed-binary abuse chain [T1553.002] that walks past Windows SmartScreen and suppresses the heuristic engines that most enterprise endpoints rely on.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence