APTMembers
APT

Signed DLL in Adware Chain Confirmed as PubNubRAT

A campaign using two DigiCert certificates issued to Chengdu entities has operated for 18 months inside Chinese-language PC-utility software. A newly surfaced DLL signed by a second Chengdu company received the first RAT classification in the cluster, while 26 IP nodes impersonating UnionPay, Tencent Cloud, and 360 Security TLS certificates reveal a sophisticated network-camouflage layer.

May 28, 2026, 05:53 (UTC+9)Last seenMay 28, 2026Severity100ByCTX TeamActorAPT23KeyBoyIOC59MITRE13

For eighteen months, a campaign built around two DigiCert code-signing certificates issued to Chengdu-registered entities moved through Chinese-language Windows environments largely beneath the noise floor — its payloads labelled adware, its delivery mechanism a well-known PC-utility ecosystem, its detection rates low enough that signed binaries slipped past Windows SmartScreen with detection ratios as low as 10 of 77 engines. That picture changed with the appearance of a single DLL.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence