
Six Rotating Certificates Keep Chinese Adware Cluster Trusted
A batch of 19 signed Win32 binaries flagged under a threat feed's 'c2-servers' label actually traces to the Ludashi/ChinaAD PUA-adware ecosystem. Twelve files share one code-signing identity while five other Chinese-registered entities rotate in as certificates get flagged or revoked.
A batch of 19 Win32 binaries flagged under a "c2-servers" threat record shows something far more mundane, and arguably more instructive, than the record's own label suggests. Twelve of the files share one code-signing identity — 成都奇鲁科技有限公司, chained under DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 — used continuously across builds first seen from May 2025 through April 2026.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read