APTMembers
APT

Revoked Certum Cert Evades 75 of 76 Engines in Ludashi Adware Pivot

Two ProZip-branded executables signed by a previously unseen Chinese entity and a certificate already revoked at deployment time surfaced on VirusTotal on 23 May 2026 with near-zero detection. The result is a deliberate operator test of the gap between formal certificate revocation and actual engine-level enforcement — a gap this campaign is now systematically exploiting.

May 29, 2026, 18:20 (UTC+9)Last seenMay 29, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC55MITRE16

Two freshly minted Windows executables, both signed by a previously unseen Chinese entity called 深圳市禹仁科技有限公司 and both carrying a Certum code-signing certificate that had already been revoked at the time of deployment, surfaced on VirusTotal on 23 May 2026 — just six days before CTX Team's analysis. One of the two files, a 346-kilobyte PE32 executable installed under C:\Program Files (x86)\ProZip\Bin\nhlj32.exe, was flagged by exactly one of 76 scanning engines.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence