FILEMembers
FILE

One Chinese Signing Identity Ties Together Sixteen 'Different' Malware Families

Thirteen of sixteen TA428-tagged files share an identical DigiCert-rooted signer chain issued to a Chengdu-registered company, despite antivirus engines splitting them into seven unrelated-looking adware family names. The signing capability survived a full certificate expiration cycle and still produced a coordinated same-day build wave in August 2026.

Aug 15, 2026, 07:01 (UTC+9)Last seenAug 15, 2026Severity72ByCTX TeamActorTA428ThunderCatsIOC54MITRE22RegionsCACNTH

The most durable artifact in a fresh batch of sixteen file indicators tagged to TA428 (alias ThunderCats) isn't a backdoor at all — it's a code-signing certificate. Thirteen of the sixteen files carry an identical signer chain issued to 成都赤侠信息科技有限公司 and rooted in DigiCert Trusted Root G4 via DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, spanning binaries as small as 95 KB and as large as 55.9 MB. Detection ratios across that cohort run from 2 out of 76 engines to 32 out of 75.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence