FILEMembers
FILE

Cert-Mill Hides Inside Chinese Adware Supply Chain

Seventeen of nineteen binaries in a Chinese PC-utility malware cluster share one DigiCert code-signing chain issued to at least five differently named shell companies. Every tagged file belongs to the Ludashi, Chinad, Jaik, or Polarwind adware lineage — not any named APT toolkit.

Jul 16, 2026, 13:50 (UTC+9)Last seenJul 16, 2026Severity77ByCTX TeamActorAPT23KeyBoyIOC47MITRE8

Seventeen of nineteen enriched binaries in a newly mapped cluster of Chinese PC-utility software carry a code-signing certificate issued through the identical "DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1" chain — yet the certificates were issued to at least five differently named Chinese companies, none of which appear to share ownership on paper.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence