C&CMembers
C&C

Two Dead Certificates Still Signing Live VPN Malware

Two unrelated shell companies' expired code-signing certificates still vouch for six VPN-branded Windows binaries flagged 'not time valid' by VirusTotal, yet the files keep circulating and drawing 12-29 static detections while single-sandbox runs often clear them as harmless. CTX Team's review finds a mature bundling operation exploiting residual trust in dead signing chains rather than a novel exploit.

Jul 11, 2026, 21:37 (UTC+9)Last seenJul 11, 2026Severity100ByCTX TeamActorSpace PiratesWebwormIOC172MITRE18

Two unrelated shell companies — one issued an EV code-signing certificate by GlobalSign, the other an OV certificate by DigiCert — are each vouching for a trio of VPN-branded Windows binaries whose leaf certificates VirusTotal now flags as "not time valid." That should mean nothing runs. Instead, both cohorts keep circulating: a "WireVPN" loader-and-DLL set signed under WEILAI NETWORK TECHNOLOGY CO., LIMITED racks up 14 to 29 flags out of 74-75 engines, while a "VPNMaster" trio signed under…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence