
Fake VPN Installers Keep Shipping Under Revoked Signing Certificates
Two trojanized VPN/proxy installer families, WireVPN and VPNMaster, have circulated for months after the code-signing certificates behind them were flagged revoked or expired. The persistence exploits the gap between formal certificate revocation and the slower-moving trust heuristics most endpoint tools actually rely on.
Two trojanized VPN and proxy installer families have kept circulating for months after the code-signing certificates behind them were marked revoked or no longer time-valid — a pattern that turns a routine trust-chain failure into an operational feature rather than a bug. One cluster, branded WireVPN, rides a GlobalSign EV certificate issued to WEILAI NETWORK TECHNOLOGY CO., LIMITED; the other, a fake VPN suite calling itself VPNMaster, rides a single DigiCert certificate issued to INNOVATIVE…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read