APTMembers
APT

Two DigiCert Certs, 18 Signed Payloads, 14 Months Unrevoked

A campaign tracked from November 2024 through at least January 2026 has distributed a modular adware-and-collection toolkit under the cover of two valid DigiCert G4 code-signing certificates issued to distinct Chinese legal entities. Every file passes Windows Authenticode validation, six carry deliberate sandbox-evasion logic, and one component has been classified as a PubNub-based remote-access trojan. Both certificates remain unrevoked and valid through 2027.

May 26, 2026, 16:35 (UTC+9)Last seenMay 27, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC62MITRE19

Eighteen Windows executables and DLLs have been circulating under the cover of two valid DigiCert Trusted G4 code-signing certificates, each issued to a distinct Chinese legal entity, across a campaign that CTX Team has tracked from November 2024 through at least January 2026. Both certificates remain unrevoked. Every file in the cohort passes Windows Authenticode validation without a SmartScreen warning.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence