C&CMembers
C&C

One EV Certificate, Two Trojans, Three Fake Windows Binaries

A trojan.jumper campaign targeting the automotive sector pairs VPN-themed malware signed with a reused GlobalSign EV certificate against three files impersonating canonical Windows system binaries. All five payloads carry appended overlay data, while a six-ASN command-and-control network with automated 89-day TLS rotation keeps the infrastructure largely invisible across 91 scanning engines.

May 28, 2026, 18:31 (UTC+9)Last seenMay 28, 2026Severity100ByCTX TeamIOC18MITRE12

Two trojan.jumper payloads circulating under the guise of a WireVPN client share an identical GlobalSign Extended Validation code-signing certificate — serial 03 A9 18 8A A5 10 C0 F8 34 34 26 BF, issued to WEILAI NETWORK TECHNOLOGY CO., LIMITED — while three companion files masquerade as canonical Windows system executables, carrying valid Microsoft signatures and zero detections across 76 scanning engines.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence