
Five Shell Companies, One Adware Campaign: DigiCert Cert Rotation Exposed
A Chinese adware operation distributing Ludashi-ecosystem malware has maintained five separate DigiCert code-signing identities across distinct legal entities, re-signing identical binaries under different certificates to survive revocation. The campaign's C2 infrastructure spans two purpose-built domain clusters fronted by Alibaba and Tencent CDNs, with sandbox evasion engineered to return clean verdicts despite AV detection ratios reaching 35/76.
Thirty-one signed Windows binaries. Five distinct Chinese legal entities. One certificate authority. The Ludashi adware ecosystem — distributed under the guise of utility software products with names like LargeFileClean, WhaleMemory, Mem Optimization Pro, DupsClean, and CipherLock — has been running a sustained code-signing rotation strategy that goes well beyond what commodity adware operators typically invest in.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read