
Shell Companies, Signed Malware, and a RAT Hidden in a PC Cleaner
Two Chengdu-registered shell companies obtained valid DigiCert code-signing certificates to launder trust onto 17 malicious Windows binaries distributed through the Ludashi PC-optimization ecosystem. The campaign has rotated signing infrastructure on a deliberate schedule since mid-2024, pairing adware-tier executables with PubNubRAT-classified DLLs while routing C2 traffic through Chinese backbone IPs that impersonate UnionPay International, 360 Browser, and Alibaba CDN.
Seventeen Windows binaries circulating across Chinese consumer software ecosystems carry valid DigiCert Trusted G4 Code Signing certificates — but the two Chengdu-registered entities that obtained those certificates appear to exist solely to launder signing trust onto malicious code. The scheme is not a one-off: CTX Team's analysis documents a deliberate rotation cycle spanning more than two years, with one entity procuring a replacement certificate within the same month its predecessor expired…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read