APTMembers
APT

13 Trojanized Updates, Two Live Certs: Inside a Chinese CDN Signing Abuse Campaign

Thirteen malicious Windows executables bearing valid, unrevoked Authenticode signatures from two Chinese software vendors have been circulating inside the update pipelines of popular consumer applications for six months. Delivered through Alibaba's Kunlun CDN via the software's own update channel, the payloads defeat file-trust and IP-level blocking simultaneously — and at least one carries patterns consistent with SQL Server authentication bypass.

Jun 3, 2026, 19:10 (UTC+9)Last seenJun 3, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC62MITRE11

Thirteen malicious Windows executables bearing valid, unrevoked Authenticode signatures from two separate Chinese software vendors have been circulating inside the update pipelines of widely-installed consumer applications — a signed-binary abuse chain [T1553.002] that walks past Authenticode-based endpoint defences on every build produced across a six-month window.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence