Expel reported that the malware operation it tracks as BaoLoader abused at least 26 code-signing certificates over roughly seven years to make malicious software appear legitimate, tying AppSuite-PDF, PDF Editor, ManualFinder, PDFTools, PDFProSuite, OneStart, and related installers to the same actor cluster. The activity was linked to repeated business registrations and certificate purchases from multiple certificate authorities, with a notable concentration of entities in Panama and Malaysia, allowing the operators to continue signing new payloads after earlier certificates were revoked.
The reporting indicates BaoLoader has often been misclassified as a potentially unwanted program and at times confused with ChromeLoader and TamperedChef, but certificate patterns, installer behavior, and campaign history point to a distinct malware ecosystem. Additional analysis of AppSuite PDF Editor and OneStart supports the broader picture of deceptive software installers and backdoor-capable delivery chains, while Expel said code-signing irregularities and certificate reuse remain key hunting signals for defenders tracking the operation.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
Expel, working with CertGraveyard.org, published an analysis concluding that BaoLoader developers abused at least 26 code-signing certificates over roughly seven years and often registered businesses directly to obtain them. The report also argued BaoLoader is distinct from ChromeLoader and TamperedChef based on certificate patterns, tactics, and campaign history.
Expel said the earliest certificate it linked to BaoLoader activity in CertGraveyard data dates to 2018, indicating the operation has been active since at least that year.
Expel assessed with high confidence that AppSuite-PDF, PDF Editor, ManualFinder, PDFTools, PDFProSuite, and OneStart were distributed by the same team it tracks as BaoLoader. It described AppSuite-PDF as an installer that downloads PDF Editor while also including a backdoor.
Expel said that after additional certificate revocations, the BaoLoader operators obtained new code-signing certificates for Onestart Technologies LLC from SSL.com and DigiCert.
After Apollo Technologies certificates were revoked, the actors used an SSL.com-issued certificate for Caerus Media LLC to sign OneStart-related files, according to Expel.
Expel reported that the developer signed OneStart with multiple Apollo Technologies Inc. code-signing certificates issued by SSL.com and GlobalSign. The report said OneStart was often downloaded unintentionally through PDF editor ads or bundled software.
Expel linked earlier BaoLoader activity to products including PDF Pro Suite, ManualsViewer, PDFFlex, and other PDF- or manual-themed applications. It also identified related certificate use for signer names such as Digital Promotions Sdn. Bhd. and Eclipse Media Inc. across these campaigns.
Expel found a DigiCert-issued Eclipse Media Inc. certificate on files uploaded under lure names such as ZoomSetup, TinyTaskSetup, WinRarSetup, and MinecraftSetup that installed Web Companion. The report also said BaoLoader-associated certificates were used to load Browser Assistant or Web Companion and that some Web Companion DLLs were re-signed by the actors.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 46 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.