C&CMembers
C&C

Three Shell Companies, One Trusted Root: Adware's Signing Shuffle

Twenty binaries from a Chinese adware/PUA toolset carry valid 'Signed' verdicts on VirusTotal, but the certificates behind them rotate through three unrelated shell companies — all chaining to the same trusted DigiCert root. The pattern lets the toolset keep its 'Signed: Valid' badge alive indefinitely even as individual certificates are swapped out underneath it.

Jul 20, 2026, 21:36 (UTC+9)Last seenJul 20, 2026Severity100ByCTX TeamActorPatchworkChinastratsIOC72MITRE17

Twenty binaries tied to a single Chinese-language adware and PUA toolset carry a valid "Signed" verdict from VirusTotal — but the certificates behind that verdict rotate through at least three different corporate identities, all validating through the same trusted chain: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1. 成都星汉云科科技有限公司 signs ten files. 北京创想界科技有限公司 signs seven more. 成都赤侠信息科技有限公司 signs a final two.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence