FILEMembers
FILE

Four Shell Companies, One DigiCert Root: China Adware's Cert-Hopping Scheme

Fifteen Windows adware installers rotate through four Chinese shell-company code-signing identities that all chain to the same DigiCert Trusted G4 root. Each identity survives only a few months before being retired and replaced, buying the payload a fresh detection-evasion window every cycle.

Jul 30, 2026, 13:44 (UTC+9)Last seenJul 30, 2026Severity100ByCTX TeamIOC31MITRE12

Fifteen Windows installers branded as GPU tuners, file-recycling tools and browser guards share a single, less advertised trait: whichever shell company's name appears on the digital signature, the trust chain underneath always resolves to the same DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 root. Over roughly a year and a half, four distinct Chinese signing identities — 成都奇鲁科技有限公司, 天津中思明达科技有限公司, 天津立方星球文化传媒有限公司 and 天津星聚时代科技有限公司 — have taken turns wearing that same trusted…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence