
Chengdu Operator Hides RAT Inside Adware Using Dual DigiCert Certs
A Chengdu-based threat actor has built a two-layer certificate-abuse architecture — valid DigiCert code-signing credentials suppressing endpoint detection, UnionPay International TLS certificates masking C2 traffic — to sustain a multi-brand fake-security-software campaign against the telecom sector. Buried inside a toolset most platforms triage as low-priority adware is dll_repa.dll, a sandbox-confirmed PubNubRAT component that gives the operator covert remote access to compromised hosts.
Nineteen of twenty Windows executables and DLLs circulating under fake Chinese security-product brands — SafeSpace, ByteLocker, DataVault, LhpMaxProtect, LhpNetSentinel, and a half-dozen others — carry valid DigiCert Trusted G4 code-signing certificates issued to two Chengdu-registered entities, a signed-binary abuse strategy [T1553.002] that drives detection ratios as low as 12 of 76 engines on the largest payloads.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read