Security researchers have uncovered a sophisticated malware campaign spanning seven years, where the perpetrators behind the AppSuite-PDF and PDF Editor systematically abused code signing certificates to legitimize their malware.

The perpetrators, tracked under the malware family name BaoLoader, have used at least 26 code signing certificates obtained through fraudulent business registrations, primarily targeting users looking for PDF editing tools and productivity applications.
The campaign demonstrates a calculated approach to manipulating certificate authorities, with the perpetrators establishing legitimate businesses in multiple jurisdictions, including Panama, Malaysia, and the United States. These entities served as fronts for obtaining code signing certificates from major certificate authorities, including SSL.com, GlobalSign, DigiCert , and Sectigo.
The malware has been distributed in various forms, including AppSuite-PDF, PDF Editor, ManualFinder, PDFTools, PDFProSuite , and OneStart, often disguised as potentially unwanted programs (PUPs) while containing backdoor.
What sets this campaign apart from typical certificate abuses is the consistent pattern of the perpetrators obtaining multiple certificates for identical company names from different certificate authorities. Expel researchers identified this unusual behavior while analyzing the CertCentral.org, noting that among the over 1,500 documented organizations with abused certificates, these perpetrators were unique in their geographic certificate patterns and systematic approach to impersonating legitimate entities.

The perpetrators’ methodology extends beyond simple certificate acquisition to include sophisticated distribution mechanisms. Files have been uploaded to platforms such as VirusTotal under numerous deceptive names, with executables appearing as “ZoomSetup,” “WinRarSetup,” “MinecraftSetup,” and various PDF-related applications. This multiple-name strategy suggests deliberate efforts to maximize infection routes by appealing to diverse user interests and needs.
The technical infrastructure behind BaoLoader reveals meticulous planning in their certificate acquisition strategies. The perpetrators established companies with media-focused names, such as GLINT SOFTWARE SDN. BHD., ECHO INFINI SDN. BHD., Summit Nexus Holdings LLC, Apollo Technologies Inc., and Caerus Media LLC. Each entity was registered with legitimate business documentation, allowing the perpetrators to bypass initial certification authority verification processes.
Analysis of certificate metadata reveals consistent enterprise serial numbers across multiple CAs for identical company names. For example, Eclipse Media Inc.’s certificates were issued by GlobalSign, SSL.com, Sectigo , and DigiCert, all containing identical enterprise registration identifiers. This approach allowed the attackers to maintain business continuity when individual certificates were revoked, seamlessly switching between CAs while maintaining the same organizational identity.

The malware's persistence mechanisms include PowerShell execution designed to load Web Companion components, executing commands that bypass execution policies, and loading assemblies from encrypted files. The campaign's evolution from simple adware distribution to backdoor deployment represents a worrying escalation in the capabilities of the perpetrators.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
