
One Signing Session Armed a Full Adware Suite With a Valid DigiCert Cert
On August 30, 2023, nine malicious components of the Chinese security product 2345PCSafe were signed in a single session using a valid DigiCert code-signing certificate issued to Shanghai 2345 Mobile Technology Co., Ltd. The certificate remains unrevoked, and payload URLs routed through Alibaba's Kunlun CDN were still serving fresh .lzma blobs as recently as May 28, 2026. The combination of a trusted vendor certificate and a legitimate CDN delivery channel renders both signature-based allow-listing and IP-level blocking largely ineffective.
On the morning of August 30, 2023, someone with access to Shanghai 2345 Mobile Technology Co., Ltd.'s code-signing infrastructure sat down and signed nine Windows components in rapid succession — SafeUpdate.dll at 7:36 AM, Optimize.dll at 7:34 AM, Exam.dll at 7:33 AM, AvScan.dll at 7:32 AM, and five more within the same narrow window.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read