
Three Chinese Firms Rotate DigiCert Certs to Keep Adware Trusted
Twenty signed Windows binaries posing as security and optimisation software are distributing the Ludashi/Polarwind adware-trojan family across a modular payload ecosystem. The operation rotates code-signing certificates across three distinct Chinese corporate entities as each accumulates antivirus detections, while its C2 infrastructure hides behind TLS certificates bearing major Chinese consumer platform hostnames to frustrate blocking.
Twenty Windows executables and DLLs — every single one carrying a valid DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 signature — are circulating under the guise of security and system-optimisation software, with the signing authority rotating across three distinct Chinese corporate entities to sustain a trusted posture as individual certificates accumulate antivirus detections.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read