FILEMembers
FILE

Revoked EV Certificate Still Signs Fake-VPN Malware for Months

A WEILAI Network Technology-signed loader trio kept shipping under a GlobalSign EV certificate VirusTotal marks revoked, alongside a separately signed VPNMaster deceptor family and a trojanized Bright Data SDK. Domains tied to the campaign refreshed TLS certificates in lockstep within a six-day window, pointing to a maturing fake-VPN distribution pipeline rather than a single dropper campaign.

Sep 13, 2026, 15:10 (UTC+9)Last seenSep 13, 2026Severity88ByCTX TeamActorAPT15ROYALAPTIOC13MITRE24

A loader-and-updater trio still carries a fully valid-looking code signature from an EV certificate that VirusTotal has explicitly marked revoked — and the operators kept building new samples under that same signing identity for roughly four months after the revocation took hold. Three files — a sideloaded DLL, its companion loader, and an updater binary that installs to C:\Windows\SysWOW64\wire\ — are signed end to end as WEILAI NETWORK TECHNOLOGY CO., LIMITED, chained up through a GlobalSign…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence