
Two Dead Certificates Still Signing Live VPN Malware
Two unrelated shell companies' expired code-signing certificates still vouch for six VPN-branded Windows binaries flagged 'not time valid' by VirusTotal, yet the files keep circulating and drawing 12-29 static detections while single-sandbox runs often clear them as harmless. CTX Team's review finds a mature bundling operation exploiting residual trust in dead signing chains rather than a novel exploit.
Two unrelated shell companies — one issued an EV code-signing certificate by GlobalSign, the other an OV certificate by DigiCert — are each vouching for a trio of VPN-branded Windows binaries whose leaf certificates VirusTotal now flags as "not time valid." That should mean nothing runs. Instead, both cohorts keep circulating: a "WireVPN" loader-and-DLL set signed under WEILAI NETWORK TECHNOLOGY CO., LIMITED racks up 14 to 29 flags out of 74-75 engines, while a "VPNMaster" trio signed under…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read