C&CMembers
C&C

One DigiCert Cert, 22 New Payloads: Inside a Chinese Adware Signing Pipeline

A Chengdu-registered entity has expanded its signed adware operation to twenty-two new Windows executables under a single still-valid DigiCert certificate, with five new command-and-control IPs added across Chinese ISPs. The operator's build pipeline reships identical compiled binaries under different product names and re-signs the same codebase iteratively, treating the certificate as a durable production asset rather than a one-time credential.

Jun 1, 2026, 17:38 (UTC+9)Last seenJun 1, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC70MITRE9

Since CTX Team's earlier coverage of this operation, twenty-two additional signed Windows executables and five new command-and-control IP addresses have surfaced under the same Chengdu-registered signing identity — all bearing a DigiCert code-signing certificate that remains valid until May 2027 and has not been revoked. The expansion confirms that the operator behind 成都奇鲁科技有限公司 (Chengdu Qilu Technology Co.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence