logo

The history of AppSuite: the certs of the BaoLoader developer

ID: 4e001193-80a9-5ef5-96b7-a7572e4ed10d

STIX ID: report--4e001193-80a9-5ef5-96b7-a7572e4ed10d

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2025-09-11

Date Updated: 2026-04-27

Author: Aaron Walton

...
...

This report details Expel and CertGraveyard's analysis of the BaoLoader ecosystem: a multi‑year campaign in which an actor group repeatedly registers companies and obtains legitimate code‑signing certificates (notably from Panama, Malaysia, and the US) to sign and distribute PUPs and backdoors (AppSuite‑PDF, PDF Editor, OneStart, etc.). The writeup maps certificate issuers, signer names, representative signed binaries and SHA256 hashes, observed behaviors (silent installers, Web Companion installs, scheduled tasks, cloudfront-first-stage, DGA-style C2), and notes overlaps and distinctions with other families (Chromeloader, TamperedChef), emphasizing certificate abuse as a key detection/hunting vector and listing actionable IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.