
APT23 Runs 18-Month Signed-Binary Campaign Behind Chinese Corporate Certs
Eight Windows executables masquerading as Chinese PC-optimization and PDF-utility software have circulated since late 2024, each carrying valid DigiCert G4 code-signing certificates issued to three distinct Chinese corporate entities. The payloads suppress sandbox verdicts while beaconing to a nine-domain C2 fleet whose TLS certificates come exclusively from the Chinese CA iTrust DV TLS CA, with subdomain names deliberately mirroring the embedded product names. CTX Team attributes the operation to APT23 with medium confidence, assessing espionage as the primary motivation.
Eight Windows executables have been circulating across Chinese-language computing environments since at least November 2024, each carrying a valid, unexpired DigiCert G4 code-signing certificate issued to one of three distinct Chinese corporate entities — and each producing uniformly clean verdicts in automated sandbox environments despite antivirus detection ratios that range as high as 34 out of 76 engines.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read