
Four Shell Companies, One DigiCert Root: China Adware's Cert-Hopping Scheme
Fifteen Windows adware installers rotate through four Chinese shell-company code-signing identities that all chain to the same DigiCert Trusted G4 root. Each identity survives only a few months before being retired and replaced, buying the payload a fresh detection-evasion window every cycle.
Fifteen Windows installers branded as GPU tuners, file-recycling tools and browser guards share a single, less advertised trait: whichever shell company's name appears on the digital signature, the trust chain underneath always resolves to the same DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 root. Over roughly a year and a half, four distinct Chinese signing identities — 成都奇鲁科技有限公司, 天津中思明达科技有限公司, 天津立方星球文化传媒有限公司 and 天津星聚时代科技有限公司 — have taken turns wearing that same trusted…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read