APTMembers
APT

Chengdu Operator Hides RAT Inside Adware Using Dual DigiCert Certs

A Chengdu-based threat actor has built a two-layer certificate-abuse architecture — valid DigiCert code-signing credentials suppressing endpoint detection, UnionPay International TLS certificates masking C2 traffic — to sustain a multi-brand fake-security-software campaign against the telecom sector. Buried inside a toolset most platforms triage as low-priority adware is dll_repa.dll, a sandbox-confirmed PubNubRAT component that gives the operator covert remote access to compromised hosts.

Jun 1, 2026, 10:22 (UTC+9)Last seenJun 1, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC89MITRE10

Nineteen of twenty Windows executables and DLLs circulating under fake Chinese security-product brands — SafeSpace, ByteLocker, DataVault, LhpMaxProtect, LhpNetSentinel, and a half-dozen others — carry valid DigiCert Trusted G4 code-signing certificates issued to two Chengdu-registered entities, a signed-binary abuse strategy [T1553.002] that drives detection ratios as low as 12 of 76 engines on the largest payloads.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence