
Signed VPN Installer Trojan Targets Food and Beverage Firms
Three PE32 executables posing as a VPN product carry an expired DigiCert certificate and active sandbox-evasion logic that fooled dynamic analysis at up to 99 percent confidence. Behind the installer sits a freshly automated C2 fleet of 40-plus algorithmically generated domains provisioned in a single scripted operation days before the campaign was observed.
Three Windows executables — VPNMaster.exe, Startup.exe, and master_vpn-service.exe — are circulating as components of a coherent VPN product installation, each carrying a DigiCert G4 code-signing certificate issued to a Singapore-registered entity called "INNOVATIVE CONNECTING PTE. LIMITED." The certificate, serial number 0C 8F 89 21 C5 36 49 3E 67 DF 84 FB 82 23 B0 92, expired on 2 April 2026, yet the binaries remain structurally signed and continue to bypass security controls on systems that…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read