
A Single Chinese Certificate Has Signed Adware for 13 Straight Months
Thirteen Windows binaries tied to the Ludashi/ChinAD adware family all carry the same valid, unrevoked DigiCert-chained certificate from a Chengdu-registered company, letting fresh builds inherit trusted-publisher status month after month. A second Chengdu signing entity and a Chinanet-hosted network layer recycling Alibaba- and UnionPay-branded TLS certificates extend the same operation — despite an upstream feed's unsupported APT29/espionage tag.
Thirteen Windows binaries submitted between April 2025 and May 2026 — spanning executables and DLLs with names like privacy_clean.exe, cclean.exe, multi_wechat.exe, and NetSentinelTray.exe — all carry the identical code-signing certificate issued to 成都奇鲁科技有限公司 (Chengdu Qilu Technology Co.), serial 0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98, chained through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 up to DigiCert Trusted Root G4.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read