C&CMembers
C&C

Shell Companies, Signed Malware, and a RAT Hidden in a PC Cleaner

Two Chengdu-registered shell companies obtained valid DigiCert code-signing certificates to launder trust onto 17 malicious Windows binaries distributed through the Ludashi PC-optimization ecosystem. The campaign has rotated signing infrastructure on a deliberate schedule since mid-2024, pairing adware-tier executables with PubNubRAT-classified DLLs while routing C2 traffic through Chinese backbone IPs that impersonate UnionPay International, 360 Browser, and Alibaba CDN.

Jun 4, 2026, 11:37 (UTC+9)Last seenJun 4, 2026Severity100ByCTX TeamIOC55MITRE17

Seventeen Windows binaries circulating across Chinese consumer software ecosystems carry valid DigiCert Trusted G4 Code Signing certificates — but the two Chengdu-registered entities that obtained those certificates appear to exist solely to launder signing trust onto malicious code. The scheme is not a one-off: CTX Team's analysis documents a deliberate rotation cycle spanning more than two years, with one entity procuring a replacement certificate within the same month its predecessor expired…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence