
Ludashi Adware Operator Pre-Positions Second DigiCert Certificate as Revocation Insurance
A follow-up investigation into the Ludashi adware campaign finds the operator has secured a second DigiCert G4 code-signing certificate under a distinct Chinese legal entity while the original remains unrevoked. Combined with a 17-IP CDN backend now confirmed to serve live payload delivery, the dual-certificate architecture reveals deliberate, multi-year evasion planning rather than reactive patching.
Eleven Windows PE files. Two distinct Chinese legal entities. A single DigiCert Trusted G4 code-signing root. And, as of this writing, every certificate still valid. The Ludashi adware campaign documented in earlier coverage has extended its operational footprint in ways that reveal deliberate, forward-looking infrastructure management rather than reactive patching.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read