
VPN Trojan Trio Shares Revoked EV Signature, Clears Sandbox Despite Flags
Three Windows binaries branded as WireVPN — wire.exe, wire.dll, and upWire.exe — all carry an identical WEILAI NETWORK TECHNOLOGY/GlobalSign EV code-signing chain that has since been revoked. A fourth file branded as VPNMaster's proxy tool uses a separate DigiCert-chained signer, pointing to two parallel operators working the same consumer-VPN-branding angle.
Three Windows binaries branded as pieces of a consumer VPN client — a small stub called wire.exe, a much larger DLL called wire.dll, and a standalone installer called upWire.exe — all carry the identical publisher chain: WEILAI NETWORK TECHNOLOGY CO., LIMITED, chained up through GlobalSign GCC R45 EV CodeSigning CA 2020 to GlobalSign's root.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read