C&CMembers
C&C

Three Chinese Firms Rotate DigiCert Certs to Keep Adware Trusted

Twenty signed Windows binaries posing as security and optimisation software are distributing the Ludashi/Polarwind adware-trojan family across a modular payload ecosystem. The operation rotates code-signing certificates across three distinct Chinese corporate entities as each accumulates antivirus detections, while its C2 infrastructure hides behind TLS certificates bearing major Chinese consumer platform hostnames to frustrate blocking.

Jun 6, 2026, 03:38 (UTC+9)Last seenJun 6, 2026Severity100ByCTX TeamActorTA551ShathakIOC136MITRE8

Twenty Windows executables and DLLs — every single one carrying a valid DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 signature — are circulating under the guise of security and system-optimisation software, with the signing authority rotating across three distinct Chinese corporate entities to sustain a trusted posture as individual certificates accumulate antivirus detections.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence