
Two Chengdu Shell Certificates Keep an Adware Pipeline Signed for Eight Months
Twelve Win32 binaries trace back to just two Chengdu-registered signing identities, both chained to a valid DigiCert Trusted G4 root, that have kept the same Ludashi/Chinad adware lineage signed and shipping since late 2025. Rather than a single malicious drop, the evidence shows a release pipeline: eight files, two signer cohorts, and at least seven consumer utility brand names, with detection ratios eroding build to build while the certificates stay untouched.
Twelve Win32 binaries pulled from a single indicator set trace back to just two corporate code-signing identities — both registered in Chengdu, both chained to a valid DigiCert Trusted G4 root — and both still actively signing new builds of the same PC-optimizer adware lineage as of June 2026. Rather than a single malicious drop, what emerges is a release pipeline: eight files across two named signer cohorts, installed under at least seven different consumer utility brand names, moving through…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read