
13 Trojanized Updates, Two Live Certs: Inside a Chinese CDN Signing Abuse Campaign
Thirteen malicious Windows executables bearing valid, unrevoked Authenticode signatures from two Chinese software vendors have been circulating inside the update pipelines of popular consumer applications for six months. Delivered through Alibaba's Kunlun CDN via the software's own update channel, the payloads defeat file-trust and IP-level blocking simultaneously — and at least one carries patterns consistent with SQL Server authentication bypass.
Thirteen malicious Windows executables bearing valid, unrevoked Authenticode signatures from two separate Chinese software vendors have been circulating inside the update pipelines of widely-installed consumer applications — a signed-binary abuse chain [T1553.002] that walks past Authenticode-based endpoint defences on every build produced across a six-month window.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read