
Single EV Certificate Signed Trojan.Jumper Trio Across Nine Sectors
A trojanised VPN installer toolchain bearing one GlobalSign Extended Validation certificate issued to 'WEILAI NETWORK TECHNOLOGY CO., LIMITED' has targeted nine industry verticals since September 2025. The certificate suppressed sandbox verdicts across two of three binaries while a three-tier C2 architecture spanning Bytedance-AS Singapore nodes, a CHINANET Sichuan IDC, and a Cloudflare-fronted .beer domain kept network-level detection minimal.
A trojanised VPN installer toolchain — three PE32 binaries all bearing a single GlobalSign Extended Validation certificate issued to "WEILAI NETWORK TECHNOLOGY CO., LIMITED" — has been circulating across nine industry verticals since at least September 2025, using a curated software-recommendation channel as its entry point and a three-tier command-and-control architecture to evade both sandbox analysis and network-level detection.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read