
Two EV Certificates Power Dual-Brand VPN Malware Evading Sandboxes
Trojanised VPN installers branded as WireVPN and VPNMaster are circulating with valid Extended Validation code-signing certificates from two separate corporate entities, producing clean sandbox verdicts despite antivirus detection rates of 10–35 out of 76 engines. A ChatGPT-branded lure domain serves as the primary distribution point, while kernel-mode driver components embedded in the package extend the operator's reach below the application layer.
Seven Windows executables masquerading as legitimate VPN software — split across two distinct product families, WireVPN and VPNMaster — are circulating with valid Extended Validation code-signing certificates from two separate corporate entities, producing clean sandbox verdicts even as antivirus engines flag them at rates between 10 and 35 out of 76.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read