
Two Shell Companies, Two DigiCert Certs, One Ludashi Campaign
A Chengdu-based operator obtained valid DigiCert code-signing certificates through two separately registered shell companies, splitting 20 malicious Windows binaries across parallel signing identities so that revoking either certificate leaves the other cluster fully operational. The campaign masquerades as routine PC-maintenance utilities while routing C2 traffic through China Unicom infrastructure presenting financial-services TLS cover. One outlier sample received a PubNubRAT sandbox classification, signalling a capability escalation beyond adware.
Twenty Windows executables and DLLs carrying currently-valid DigiCert code-signing certificates are circulating across telecom-sector endpoints, each one disguised as a routine Windows system utility — a PC cleaner, a BSOD repair tool, a browser protection suite — and each one backed by a C2 cluster that routes through China Unicom's backbone while presenting financial-services TLS cover.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read