
One Chinese Certificate Signed Nine Months of Ludashi Adware Builds
A single DigiCert-chained code-signing certificate from 成都奇鲁科技有限公司 has underwritten eight of nine binaries in a Ludashi-branded adware cluster spanning October 2025 to June 2026. Detection ratios swing wildly across builds while the operator never needed new signing infrastructure.
The most durable piece of infrastructure behind a sprawling family of Chinese system-utility adware is not a server or a domain — it is a single code-signing certificate. Eight of nine binaries examined in this cluster carry an identical signer chain: 成都奇鲁科技有限公司, chained through DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 up to DigiCert's root, with certificate serial 0D 07 8E 70 EA EE 48 FF EB 95 76 BD D4 00 BE 98.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read