APTMembers
APT

Trojanized Adware Chain Hides Behind Bank's TLS Identity for 12 Months

Twenty Windows executables bearing a currently-valid DigiCert code-signing certificate issued to a Chinese entity have circulated as trojanized PC-utility components since May 2025. Simultaneously, seventeen Chinese ISP-assigned IPs present TLS certificates issued to a major payment-card network — infrastructure with no relationship to that institution — to mask backend traffic from network controls.

May 26, 2026, 10:12 (UTC+9)Last seenMay 26, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC39MITRE8

Twenty Windows executables bearing a currently-valid DigiCert code-signing certificate issued to the Chinese entity 成都奇鲁科技有限公司 have been circulating as trojanized PC-utility components since at least May 2025 — all signed under a single certificate serial (0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98, thumbprint EC5BB0C4BE5D6F7CD9D863D6585CF1F3EF58FDA0) that remains unrevoked and valid through May 2027.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence