
Three VPN-Branded Signing Identities Share One C2 Certificate
A revoked WEILAI EV certificate, a still-valid INNOVATIVE CONNECTING DigiCert chain, and a legitimate Bright Data signature are backing three unrelated 'VPN' and proxy binaries — each hiding a different payload. All three converge on a single self-signed TLS certificate served from six IPs in Bytedance and Zenlayer space.
A revoked EV certificate from a company called WEILAI NETWORK TECHNOLOGY CO., LIMITED is still riding inside binaries that call themselves WireVPN. A separate, still-valid DigiCert chain issued to INNOVATIVE CONNECTING PTE. LIMITED backs a VPNMaster installer that sandboxes clean despite carrying a trojan label. And a validly signed Bright Data Ltd proxy-SDK component — the kind of software that legitimately resells residential IP addresses — comes back from a sandbox pass as a…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read