
Three Valid Chinese Code-Signing Certs Push Adware Past AV, Sandboxes
Three separate DigiCert code-signing identities — Shanghai Oriental Webcasting, Shenzhen Kaixin Kangaroo, and Shanghai 2345 Mobile Technology — are signing installer families that up to 47 of 77 antivirus engines flag as adware while behavioral sandboxes rate them clean. Behind the payloads, a five-IP Guangdong cluster fronts C2 traffic behind a single TLS certificate spoofing Huawei's AppGallery/HiCloud CDN.
Three legitimately issued DigiCert code-signing certificates — bearing the corporate names Shanghai Oriental Webcasting Co. Ltd., Shenzhen Kaixin Kangaroo Technology Co., Ltd., and Shanghai 2345 Mobile Technology Co., Ltd. — sit atop a wave of Chinese consumer-software installers that up to 47 of 77 antivirus engines now flag as adware, even as the same binaries clear behavioral sandboxes as harmless.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read