
Trojanized Adware Chain Hides Behind Bank's TLS Identity for 12 Months
Twenty Windows executables bearing a currently-valid DigiCert code-signing certificate issued to a Chinese entity have circulated as trojanized PC-utility components since May 2025. Simultaneously, seventeen Chinese ISP-assigned IPs present TLS certificates issued to a major payment-card network — infrastructure with no relationship to that institution — to mask backend traffic from network controls.
Twenty Windows executables bearing a currently-valid DigiCert code-signing certificate issued to the Chinese entity 成都奇鲁科技有限公司 have been circulating as trojanized PC-utility components since at least May 2025 — all signed under a single certificate serial (0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98, thumbprint EC5BB0C4BE5D6F7CD9D863D6585CF1F3EF58FDA0) that remains unrevoked and valid through May 2027.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read