C&CMembers
C&C

Ludashi Adware Operator Pre-Positions Second DigiCert Certificate as Revocation Insurance

A follow-up investigation into the Ludashi adware campaign finds the operator has secured a second DigiCert G4 code-signing certificate under a distinct Chinese legal entity while the original remains unrevoked. Combined with a 17-IP CDN backend now confirmed to serve live payload delivery, the dual-certificate architecture reveals deliberate, multi-year evasion planning rather than reactive patching.

Jun 8, 2026, 23:57 (UTC+9)Last seenJun 8, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC92MITRE5

Eleven Windows PE files. Two distinct Chinese legal entities. A single DigiCert Trusted G4 code-signing root. And, as of this writing, every certificate still valid. The Ludashi adware campaign documented in earlier coverage has extended its operational footprint in ways that reveal deliberate, forward-looking infrastructure management rather than reactive patching.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence