
CapableWin Adware Suite Signed in Nine Minutes, Certificate Still Live
Seven Windows executables branded as a Chinese-language PC utility were compiled, signed, and deployed within a nine-minute window using a valid GlobalSign certificate obtained three months in advance. The suite routes traffic through a 20-node Wangsu CDN pool shared with major Chinese consumer platforms, blending malicious delivery with legitimate traffic at the network layer. The certificate remains unrevoked despite detection rates reaching 39 of 77 AV engines across the suite.
Seven Windows executables branded as "CapableWin" — a Chinese-language PC utility marketed as 全能电脑助手, or "All-in-One PC Assistant" — were compiled, versioned, and signed within a nine-minute window on the morning of 8 September 2025, all carrying a currently-valid GlobalSign code-signing certificate issued to Beijing entity 北京华网智讯软件有限公司 that remains unrevoked despite detection rates reaching 39 of 77 engines across the suite.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read