
Three Shell Companies, One Trusted Root: Adware's Signing Shuffle
Twenty binaries from a Chinese adware/PUA toolset carry valid 'Signed' verdicts on VirusTotal, but the certificates behind them rotate through three unrelated shell companies — all chaining to the same trusted DigiCert root. The pattern lets the toolset keep its 'Signed: Valid' badge alive indefinitely even as individual certificates are swapped out underneath it.
Twenty binaries tied to a single Chinese-language adware and PUA toolset carry a valid "Signed" verdict from VirusTotal — but the certificates behind that verdict rotate through at least three different corporate identities, all validating through the same trusted chain: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1. 成都星汉云科科技有限公司 signs ten files. 北京创想界科技有限公司 signs seven more. 成都赤侠信息科技有限公司 signs a final two.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read