APTMembers
APT

Two Chengdu Shell Certificates Keep an Adware Pipeline Signed for Eight Months

Twelve Win32 binaries trace back to just two Chengdu-registered signing identities, both chained to a valid DigiCert Trusted G4 root, that have kept the same Ludashi/Chinad adware lineage signed and shipping since late 2025. Rather than a single malicious drop, the evidence shows a release pipeline: eight files, two signer cohorts, and at least seven consumer utility brand names, with detection ratios eroding build to build while the certificates stay untouched.

Jul 30, 2026, 13:33 (UTC+9)Last seenJul 30, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC31MITRE11

Twelve Win32 binaries pulled from a single indicator set trace back to just two corporate code-signing identities — both registered in Chengdu, both chained to a valid DigiCert Trusted G4 root — and both still actively signing new builds of the same PC-optimizer adware lineage as of June 2026. Rather than a single malicious drop, what emerges is a release pipeline: eight files across two named signer cohorts, installed under at least seven different consumer utility brand names, moving through…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence