
One Unrevoked Certificate, 17 Payloads, Eleven Months of Signed Adware
A single DigiCert G4 code-signing certificate issued to a Chinese entity has anchored at least 17 Ludashi-family payloads across eleven months without triggering revocation, despite detection ratios reaching 34 out of 76 antivirus engines. On the same day researchers collected the freshest samples, two new executables appeared under a separately revoked Certum certificate — one evading 75 of 76 engines — signaling an active signing-identity rotation already in progress.
Seventeen distinct Windows executables. Six product identities. Eleven months of continuous distribution. All of it bound together by a single DigiCert G4 code-signing certificate issued to the Chinese entity 成都奇鲁科技有限公司 (Chengdu Qilu Technology Co., Ltd.) — a certificate that, as of this writing, remains valid, unrevoked, and good until May 2027.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read