APTMembers
APT

Two Shell Companies, Two DigiCert Certs, One Ludashi Campaign

A Chengdu-based operator obtained valid DigiCert code-signing certificates through two separately registered shell companies, splitting 20 malicious Windows binaries across parallel signing identities so that revoking either certificate leaves the other cluster fully operational. The campaign masquerades as routine PC-maintenance utilities while routing C2 traffic through China Unicom infrastructure presenting financial-services TLS cover. One outlier sample received a PubNubRAT sandbox classification, signalling a capability escalation beyond adware.

May 29, 2026, 19:27 (UTC+9)Last seenMay 29, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC39MITRE6

Twenty Windows executables and DLLs carrying currently-valid DigiCert code-signing certificates are circulating across telecom-sector endpoints, each one disguised as a routine Windows system utility — a PC cleaner, a BSOD repair tool, a browser protection suite — and each one backed by a C2 cluster that routes through China Unicom's backbone while presenting financial-services TLS cover.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence