APTMembers
APT

Valid NordVPN Certificate Masks Signed Dropper, Zero AV Hits

A Win32 executable carrying a fully valid GlobalSign EV signature for 'nordvpn s.a.' sits under a spoofed NordUpdater path with randomized filenames. The trusted chain pushes AV detection to 0/75, even as VirusTotal's Sigma engine still logs six behavioral rule matches underneath.

Jul 17, 2026, 05:32 (UTC+9)Last seenJul 17, 2026Severity100ByCTX TeamActorComment CrewByzantine CandorIOC12MITRE5

A single Win32 executable sits at the center of this campaign, and its most interesting property is not what it does but what it is trusted to do. The file carries a fully valid GlobalSign EV code-signing chain — "nordvpn s.a.," chained through GlobalSign GCC R45 EV CodeSigning CA 2020 up to GlobalSign Root CA - R3 — with a signing date of July 13, 2026 and a product string reading "NordVPN," version 8.7.2.0. Every certificate in that chain shows a "Valid" status.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence