APTMembers
APT

APT23 Runs 18-Month Signed-Binary Campaign Behind Chinese Corporate Certs

Eight Windows executables masquerading as Chinese PC-optimization and PDF-utility software have circulated since late 2024, each carrying valid DigiCert G4 code-signing certificates issued to three distinct Chinese corporate entities. The payloads suppress sandbox verdicts while beaconing to a nine-domain C2 fleet whose TLS certificates come exclusively from the Chinese CA iTrust DV TLS CA, with subdomain names deliberately mirroring the embedded product names. CTX Team attributes the operation to APT23 with medium confidence, assessing espionage as the primary motivation.

May 26, 2026, 09:41 (UTC+9)Last seenMay 26, 2026Severity77ByCTX TeamActorAPT23KeyBoyIOC34MITRE13

Eight Windows executables have been circulating across Chinese-language computing environments since at least November 2024, each carrying a valid, unexpired DigiCert G4 code-signing certificate issued to one of three distinct Chinese corporate entities — and each producing uniformly clean verdicts in automated sandbox environments despite antivirus detection ratios that range as high as 34 out of 76 engines.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence