FILEMembers
FILE

Fake Anti-Cheat Installer Hides Beacon Behind China Unicom, CDN Certs

A validly signed installer impersonating 'Anti-Cheat Expert' anti-cheat software carries an appended overlay and split sandbox verdicts. The ten linked IPs sit almost entirely on China Unicom backbone ASNs and mimic Tencent, WeGame, and ChinaNetCenter TLS certificates, despite a 'Confucius' beacon attribution resting on thin engine corroboration.

Aug 13, 2026, 22:37 (UTC+9)Last seenAug 13, 2026Severity69ByCTX TeamActorConfuciusIOC14

The most concrete artefact in this record is a single file: an installer named ACE-Setup.exe, signed end-to-end under a valid DigiCert-anchored chain running from ACEVILLE PTE LTD through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 up to DigiCert Trusted Root G4. Its product string reads "Anti-Cheat Expert," and its embedded file paths reference two specific games — Delta Force and ABInfinite — placing the binary inside the exact directory structure…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence