C&CMembers
C&C

Trojanized Security Suite Uses Valid DigiCert Cert to Blind Sandboxes

Nine PE32 components masquerading as a legitimate Chinese consumer security product carry a currently-valid DigiCert code-signing certificate, direct-syscall evasion, and CDN-blended payload delivery. The combination collapses sandbox verdicts to zero while roughly half of static antivirus engines still flag the files.

May 28, 2026, 22:40 (UTC+9)Last seenMay 29, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC37MITRE22

Nine PE32 components masquerading as a legitimate Chinese consumer security product are circulating with a currently-valid DigiCert code-signing certificate, a direct-syscall evasion technique confirmed by YARA, and payload delivery routed through Alibaba's KunlunCan CDN — a combination that collapses sandbox verdicts to zero while roughly half of antivirus engines still flag the files on static analysis alone. The gap between those two numbers is the operational story of this campaign.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence