APTMembers
APT

Single EV Certificate Signed Trojan.Jumper Trio Across Nine Sectors

A trojanised VPN installer toolchain bearing one GlobalSign Extended Validation certificate issued to 'WEILAI NETWORK TECHNOLOGY CO., LIMITED' has targeted nine industry verticals since September 2025. The certificate suppressed sandbox verdicts across two of three binaries while a three-tier C2 architecture spanning Bytedance-AS Singapore nodes, a CHINANET Sichuan IDC, and a Cloudflare-fronted .beer domain kept network-level detection minimal.

May 26, 2026, 09:59 (UTC+9)Last seenMay 26, 2026Severity100ByCTX TeamActorTA551ShathakIOC10MITRE29

A trojanised VPN installer toolchain — three PE32 binaries all bearing a single GlobalSign Extended Validation certificate issued to "WEILAI NETWORK TECHNOLOGY CO., LIMITED" — has been circulating across nine industry verticals since at least September 2025, using a curated software-recommendation channel as its entry point and a three-tier command-and-control architecture to evade both sandbox analysis and network-level detection.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence