
Two Chinese Signing Certs Feed One Adware Pipeline, RAT Flag Emerges
Sixteen of twenty-two files in this cluster carry valid DigiCert Trusted G4 signatures issued to two different Chinese corporate identities, both distributing the same Ludashi/PolarWind adware family. One signed component drew a sandbox verdict naming embedded 'PubNubRAT' capability despite another sandbox calling it clean.
Sixteen of the twenty-two files catalogued in this cluster carry "Valid" status DigiCert Trusted G4 Code Signing chains — the exact same certificate authority, issued to two different Chinese corporate identities, distributing what VirusTotal's community consistently labels as the Ludashi/PolarWind adware-PUA family. The larger cohort, twelve files signed by 北京创想界科技有限公司, spans a detection range from 5/76 up to 34/77 across a size band running from 110 KB up to 2,571 KB.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read