
Trojanized Security Suite Uses Valid DigiCert Cert to Blind Sandboxes
Nine PE32 components masquerading as a legitimate Chinese consumer security product carry a currently-valid DigiCert code-signing certificate, direct-syscall evasion, and CDN-blended payload delivery. The combination collapses sandbox verdicts to zero while roughly half of static antivirus engines still flag the files.
Nine PE32 components masquerading as a legitimate Chinese consumer security product are circulating with a currently-valid DigiCert code-signing certificate, a direct-syscall evasion technique confirmed by YARA, and payload delivery routed through Alibaba's KunlunCan CDN — a combination that collapses sandbox verdicts to zero while roughly half of antivirus engines still flag the files on static analysis alone. The gap between those two numbers is the operational story of this campaign.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read