APTMembers
APT

Four Chinese Shell Firms, One DigiCert Chain, One Hidden RAT

Twenty Chinese-language PC-optimizer and wallpaper binaries carry code-signing certificates from four distinct shell companies — yet all four chains root to the same DigiCert Trusted G4 CA. Detection swings within single-signer cohorts and a build re-signed under two identities within a month suggest one operator rotating disposable corporate masks rather than four genuine vendors.

Aug 25, 2026, 14:37 (UTC+9)Last seenAug 25, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC46MITRE28

Twenty Chinese-language "PC optimizer" and wallpaper-app binaries in this catalog carry code-signing certificates from four different corporate entities — 成都奇鲁科技有限公司, 北京创想界科技有限公司, 成都盈畅时代文化传播有限公司, and 成都赤侠信息科技有限公司 — and every single one of those certificates chains to the identical issuing authority, "DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1." That is not four vendors independently buying trust from the same certificate authority; the detection spread inside each cohort argues…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence