
Two 'Rival' Chinese Software Brands Share One Signing Chain
Fourteen signed Win32 binaries posing as an input-method app and a photo-viewer suite from two separate Shanghai vendors trace to the same DigiCert code-signing root and a single cross-brand YARA fingerprint. VirusTotal flags 25-47 of ~77 engines as adware/trojan despite valid, unrevoked certificates.
Fourteen signed Win32 binaries surfaced carrying the trusted names of two separate Chinese software vendors — a "万能五笔输入法" input-method utility from Shanghai Oriental Webcasting Co. Ltd. and a "2345看图王" photo-viewer suite from Shanghai 2345 Mobile Technology Co., Ltd. — yet both cohorts chain to the same DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 root, and a single YARA rule fires across samples signed by each.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read