
Revoked EV Cert and Live Bright Data Signature Both Weaponized
A revoked WEILAI NETWORK TECHNOLOGY EV certificate keeps signing fake VPN builds months after being pulled, while a currently valid Bright Data/DigiCert signature covers files tagged as a PBot stealer. Together they show two operators treating code-signing trust as disposable rather than protected.
Three separate builds of a fake VPN client — upWire.exe, wire.exe and wire.dll — carry the exact same EV code-signing certificate from a company called WEILAI NETWORK TECHNOLOGY CO., LIMITED, and every one of them was signed and distributed well after VirusTotal's own signature chain marked that certificate "not time valid" and its trust "revoked." That is not a one-off scan artifact.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read