C&CMembers
C&C

Two Chinese Signing Certs Feed One Adware Pipeline, RAT Flag Emerges

Sixteen of twenty-two files in this cluster carry valid DigiCert Trusted G4 signatures issued to two different Chinese corporate identities, both distributing the same Ludashi/PolarWind adware family. One signed component drew a sandbox verdict naming embedded 'PubNubRAT' capability despite another sandbox calling it clean.

Jul 13, 2026, 21:38 (UTC+9)Last seenJul 13, 2026Severity100ByCTX TeamActorTA551ShathakIOC97MITRE47

Sixteen of the twenty-two files catalogued in this cluster carry "Valid" status DigiCert Trusted G4 Code Signing chains — the exact same certificate authority, issued to two different Chinese corporate identities, distributing what VirusTotal's community consistently labels as the Ludashi/PolarWind adware-PUA family. The larger cohort, twelve files signed by 北京创想界科技有限公司, spans a detection range from 5/76 up to 34/77 across a size band running from 110 KB up to 2,571 KB.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence