
One DigiCert Certificate Binds 18 Malicious Ludashi Components Through 2027
A modular adware framework distributed under the Chinese Ludashi brand uses a single valid DigiCert G4 code-signing certificate to suppress sandbox verdicts across 18 Windows PE files. Its C2 infrastructure compounds the evasion by presenting TLS certificates bearing UnionPay International and Alibaba CDN wildcards, making malicious traffic indistinguishable from legitimate Chinese financial and CDN flows.
Eighteen Windows PE files — a mix of executables and DLLs spanning a full PC utility lifecycle, from disk defragmentation to a lockscreen manager to an uninstaller — are circulating under the Ludashi (鲁大师) software brand, every one of them bearing an identical, currently-valid DigiCert Trusted G4 code-signing certificate issued to the Chengdu-registered entity 成都奇鲁科技有限公司 (Chengdu Qilu Technology Co. Ltd.).
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read