APTMembers
APT

Fake VPN Installers Keep Shipping Under Revoked Signing Certificates

Two trojanized VPN/proxy installer families, WireVPN and VPNMaster, have circulated for months after the code-signing certificates behind them were flagged revoked or expired. The persistence exploits the gap between formal certificate revocation and the slower-moving trust heuristics most endpoint tools actually rely on.

Aug 16, 2026, 14:29 (UTC+9)Last seenAug 16, 2026Severity88ByCTX TeamActorAPT15ROYALAPTIOC30MITRE8

Two trojanized VPN and proxy installer families have kept circulating for months after the code-signing certificates behind them were marked revoked or no longer time-valid — a pattern that turns a routine trust-chain failure into an operational feature rather than a bug. One cluster, branded WireVPN, rides a GlobalSign EV certificate issued to WEILAI NETWORK TECHNOLOGY CO., LIMITED; the other, a fake VPN suite calling itself VPNMaster, rides a single DigiCert certificate issued to INNOVATIVE…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence