C&CMembers
C&C

One Signing Session Armed a Full Adware Suite With a Valid DigiCert Cert

On August 30, 2023, nine malicious components of the Chinese security product 2345PCSafe were signed in a single session using a valid DigiCert code-signing certificate issued to Shanghai 2345 Mobile Technology Co., Ltd. The certificate remains unrevoked, and payload URLs routed through Alibaba's Kunlun CDN were still serving fresh .lzma blobs as recently as May 28, 2026. The combination of a trusted vendor certificate and a legitimate CDN delivery channel renders both signature-based allow-listing and IP-level blocking largely ineffective.

Jun 2, 2026, 01:59 (UTC+9)Last seenJun 2, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC56MITRE2

On the morning of August 30, 2023, someone with access to Shanghai 2345 Mobile Technology Co., Ltd.'s code-signing infrastructure sat down and signed nine Windows components in rapid succession — SafeUpdate.dll at 7:36 AM, Optimize.dll at 7:34 AM, Exam.dll at 7:33 AM, AvScan.dll at 7:32 AM, and five more within the same narrow window.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence