APTMembers
APT

Three DigiCert Certs, One Builder: Inside a Chinese Adware Signing Pipeline

A modular Windows toolkit deploying as consumer software across Chinese distribution channels has been systematically acquiring legitimate DigiCert code-signing certificates under multiple registered Chinese companies. The campaign's 41 signed PE32 files and 20-IP CDN infrastructure reveal a mature signing pipeline designed to survive certificate revocation — and one component has drawn a PubNubRAT sandbox classification.

May 29, 2026, 01:53 (UTC+9)Last seenMay 29, 2026Severity100ByCTX TeamActorAPT33MagnalliumIOC123MITRE15

Somewhere between a disk-cleaner utility and a remote-access implant, a modular Windows toolkit has been quietly circulating across Chinese software distribution channels, its every component bearing a valid DigiCert code-signing certificate issued to a registered Chinese legal entity. The campaign — tracked by CTX Team across at least 41 PE32 files and 20 confirmed network endpoints — deploys under four consumer-software personas (DupsClean, LargeFileClean, BirdWallpaper, and BlueDoveUnist)…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence