
Trojanized UltraSurf Proxy Rides Expired Cert Into 2026
A repackaged UltraSurf/Ultrareach build keeps circulating on a code-signing chain whose leaf certificate expired in 2024 but whose GlobalSign root and intermediate remain valid, leaving sandboxes split between 'clean proxy' and 'Glupteba2 trojan.' Five IPs on a single Hurricane Electric ASN rotate weekly self-signed certificates under invented company names, pointing to disposable proxy infrastructure behind the same operation.
A Win32 build of the UltraSurf/Ultrareach censorship-circumvention proxy — a tool millions have used to punch through national firewalls — is still circulating years after the code-signing certificate underpinning it expired. The leaf certificate, issued to "Ultrareach Internet Corp." and valid from June 9, 2021 to June 9, 2024, is now flagged by validators as "not time valid," yet the GlobalSign intermediate and root certificates above it in the chain remain valid through 2029 and 2030.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read