APTMembers
APT

Fourth Shell-Company Signer Joins Chinese Adware Cert-Farming Pipeline

A Ludashi/PolarWind-linked signing operation has added a fourth disposable Chinese shell-company certificate and a new packing technique never seen in earlier builds. Two fresh binaries signed under DigiCert's Trusted G4 chain now show high-entropy .rsrc packing, while a fifth config subdomain slots into an established hosting template.

Jul 25, 2026, 05:36 (UTC+9)Last seenJul 25, 2026Severity100ByCTX TeamActorTA428ThunderCatsIOC34

A Chinese code-signing operation that CTX Team has tracked as a persistent Ludashi/PolarWind adware-bundler pipeline has picked up a fourth disposable signing identity — and, alongside it, a packing technique the earlier builds never used. The signer, 武汉诺沃网络科技有限公司, obtained its certificate from DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 in January 2026 and used it to sign a 4,533 KB binary, instantview_service.exe, that first appeared with a 5/75 detection ratio — by far the…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence