
Fourth Shell-Company Signer Joins Chinese Adware Cert-Farming Pipeline
A Ludashi/PolarWind-linked signing operation has added a fourth disposable Chinese shell-company certificate and a new packing technique never seen in earlier builds. Two fresh binaries signed under DigiCert's Trusted G4 chain now show high-entropy .rsrc packing, while a fifth config subdomain slots into an established hosting template.
A Chinese code-signing operation that CTX Team has tracked as a persistent Ludashi/PolarWind adware-bundler pipeline has picked up a fourth disposable signing identity — and, alongside it, a packing technique the earlier builds never used. The signer, 武汉诺沃网络科技有限公司, obtained its certificate from DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 in January 2026 and used it to sign a 4,533 KB binary, instantview_service.exe, that first appeared with a 5/75 detection ratio — by far the…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read