APTMembers
APT

CapableWin Adware Suite Signed in Nine Minutes, Certificate Still Live

Seven Windows executables branded as a Chinese-language PC utility were compiled, signed, and deployed within a nine-minute window using a valid GlobalSign certificate obtained three months in advance. The suite routes traffic through a 20-node Wangsu CDN pool shared with major Chinese consumer platforms, blending malicious delivery with legitimate traffic at the network layer. The certificate remains unrevoked despite detection rates reaching 39 of 77 AV engines across the suite.

Jun 4, 2026, 23:26 (UTC+9)Last seenJun 4, 2026Severity100ByCTX TeamActorMustang PandaHoneyMyteIOC34

Seven Windows executables branded as "CapableWin" — a Chinese-language PC utility marketed as 全能电脑助手, or "All-in-One PC Assistant" — were compiled, versioned, and signed within a nine-minute window on the morning of 8 September 2025, all carrying a currently-valid GlobalSign code-signing certificate issued to Beijing entity 北京华网智讯软件有限公司 that remains unrevoked despite detection rates reaching 39 of 77 engines across the suite.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence