C&CMembers
C&C

Two Vendor Signatures, One Stealer: VPN Installers Abuse Trust Chains

Files signed by WEILAI NETWORK TECHNOLOGY (an expired GlobalSign EV certificate) and by Bright Data Ltd (a fully valid DigiCert-chained signature) both wrap VPN-branded installers that sandboxes tie to a PBot stealer classification. Detection ratios swing wildly between sibling builds sharing the same signer, undermining single-sample VirusTotal trust.

Aug 5, 2026, 11:41 (UTC+9)Last seenAug 5, 2026Severity100ByCTX TeamActorSpace PiratesWebwormIOC54MITRE17

Three files circulating under VPN branding this year carry a code-signing chain that VirusTotal's own signer inspection flags as broken. The signer field reads "WEILAI NETWORK TECHNOLOGY CO., LIMITED," countersigned through GlobalSign GCC R45 EV CodeSigning CA 2020, and every one of the three samples' signer-details blocks returns the same line: "This certificate or one of the certificates in the certificate chain is not time valid." That should be a hard stop for any endpoint relying on…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence