C&CMembers
C&C

Three VPN-Branded Signing Identities Share One C2 Certificate

A revoked WEILAI EV certificate, a still-valid INNOVATIVE CONNECTING DigiCert chain, and a legitimate Bright Data signature are backing three unrelated 'VPN' and proxy binaries — each hiding a different payload. All three converge on a single self-signed TLS certificate served from six IPs in Bytedance and Zenlayer space.

Aug 18, 2026, 14:28 (UTC+9)Last seenAug 18, 2026Severity100ByCTX TeamActorAPT15ROYALAPTIOC24MITRE14

A revoked EV certificate from a company called WEILAI NETWORK TECHNOLOGY CO., LIMITED is still riding inside binaries that call themselves WireVPN. A separate, still-valid DigiCert chain issued to INNOVATIVE CONNECTING PTE. LIMITED backs a VPNMaster installer that sandboxes clean despite carrying a trojan label. And a validly signed Bright Data Ltd proxy-SDK component — the kind of software that legitimately resells residential IP addresses — comes back from a sandbox pass as a…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence