
Ludashi Adware Operator Rotates to Third DigiCert Certificate Across Three Chinese Entities
A follow-up snapshot of the Ludashi/LuDaShi adware campaign reveals a third DigiCert G4 code-signing certificate issued to a third distinct Chinese legal entity, completing a documented pattern of deliberate identity rotation. The campaign's C2 pool has simultaneously expanded to 14 IP addresses across six Chinese ISP autonomous systems, all unified by a single Sectigo DV wildcard certificate whose Subject Alternative Names include major Chinese consumer brands.
Since CTX Team's earlier coverage of the Ludashi/LuDaShi adware ecosystem, 26 additional signed PE files and 97 IP addresses have surfaced, and the most operationally significant development is not the volume — it is what the new files reveal about how the operator manages its code-signing infrastructure. A third DigiCert G4 code-signing certificate, issued to a third distinct Chinese legal entity, has now appeared in the campaign, completing a picture of deliberate, institutionalized identity…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read