
One DigiCert Cert, 22 New Payloads: Inside a Chinese Adware Signing Pipeline
A Chengdu-registered entity has expanded its signed adware operation to twenty-two new Windows executables under a single still-valid DigiCert certificate, with five new command-and-control IPs added across Chinese ISPs. The operator's build pipeline reships identical compiled binaries under different product names and re-signs the same codebase iteratively, treating the certificate as a durable production asset rather than a one-time credential.
Since CTX Team's earlier coverage of this operation, twenty-two additional signed Windows executables and five new command-and-control IP addresses have surfaced under the same Chengdu-registered signing identity — all bearing a DigiCert code-signing certificate that remains valid until May 2027 and has not been revoked. The expansion confirms that the operator behind 成都奇鲁科技有限公司 (Chengdu Qilu Technology Co.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read