FILEMembers
FILE

Two EV Certificates Power Dual-Brand VPN Malware Evading Sandboxes

Trojanised VPN installers branded as WireVPN and VPNMaster are circulating with valid Extended Validation code-signing certificates from two separate corporate entities, producing clean sandbox verdicts despite antivirus detection rates of 10–35 out of 76 engines. A ChatGPT-branded lure domain serves as the primary distribution point, while kernel-mode driver components embedded in the package extend the operator's reach below the application layer.

Jun 2, 2026, 02:13 (UTC+9)Last seenJun 2, 2026Severity100ByCTX TeamActorBariumWicked SpiderIOC51MITRE20

Seven Windows executables masquerading as legitimate VPN software — split across two distinct product families, WireVPN and VPNMaster — are circulating with valid Extended Validation code-signing certificates from two separate corporate entities, producing clean sandbox verdicts even as antivirus engines flag them at rates between 10 and 35 out of 76.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence