
Two Adware Families Share One GlobalSign EV Cert Chain
A feed labeled this cluster APT28 espionage tooling, but VirusTotal enrichment resolves it to two unrelated adware installers and a recycled redirect-gate infrastructure. The one solid link between them is a shared GlobalSign EV code-signing intermediate — not shared authorship, but a common certificate supply chain.
Two commodity adware installers with nothing else in common — different file types, different packers, different threat labels, submitted sixteen months apart — chain to the exact same GlobalSign intermediate certificate. That single overlap, buried inside a feed-tagged "APT28" cluster, turns out to be the most concrete, independently verifiable signal in the entire dataset, and it has nothing to do with espionage tradecraft.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read