
Valid NordVPN Certificate Masks Signed Dropper, Zero AV Hits
A Win32 executable carrying a fully valid GlobalSign EV signature for 'nordvpn s.a.' sits under a spoofed NordUpdater path with randomized filenames. The trusted chain pushes AV detection to 0/75, even as VirusTotal's Sigma engine still logs six behavioral rule matches underneath.
A single Win32 executable sits at the center of this campaign, and its most interesting property is not what it does but what it is trusted to do. The file carries a fully valid GlobalSign EV code-signing chain — "nordvpn s.a.," chained through GlobalSign GCC R45 EV CodeSigning CA 2020 up to GlobalSign Root CA - R3 — with a signing date of July 13, 2026 and a product string reading "NordVPN," version 8.7.2.0. Every certificate in that chain shows a "Valid" status.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read