APTMembers
APT

Dual DigiCert Certs Cloak Adware-to-RAT Campaign Across 19 Payloads

Nineteen signed Windows binaries tied to two Chinese-registered entities have been distributing a Ludashi/PolarWind adware framework with an embedded RAT-capable core for at least eight months. Valid DigiCert certificates, active sandbox-detection logic, and CDN-mimicking TLS fingerprints combine to leave most endpoint products blind to the operation's malicious tier.

May 28, 2026, 21:56 (UTC+9)Last seenMay 28, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC72MITRE20

##A Single Certificate, Nineteen Signed Payloads, and a RAT Hidden Inside an Adware Framework Nineteen Windows binaries carrying valid DigiCert code-signing certificates — issued to two distinct Chinese-registered entities — have been circulating across Mandarin-language software distribution channels for at least eight months, wrapping a Ludashi/PolarWind adware framework around a RAT-capable core that most endpoint products still cannot see clearly.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence