APTMembers
APT

Expired and Valid Code-Signing Certificates Both Fuel VPN Malware

Three signer identities — WEILAI NETWORK TECHNOLOGY, INNOVATIVE CONNECTING PTE. LIMITED, and Bright Data Ltd — anchor a cluster of VPN and proxy installers that keep circulating despite lapsed certificates, while a fully valid Bright Data signature hides a PBot stealer. A separate, larger tail of disposable brand-impersonation domains shares hosting and certificate fingerprints, pointing to commodity infrastructure rather than a single espionage operation.

Jul 10, 2026, 19:27 (UTC+9)Last seenJul 10, 2026Severity100ByCTX TeamActorEvilnumDeathStalkerIOC91MITRE18

Three code-signing identities — WEILAI NETWORK TECHNOLOGY CO., LIMITED, Bright Data Ltd, and INNOVATIVE CONNECTING PTE. LIMITED — anchor a cluster of VPN and proxy installers now circulating with a shared defect: the certificates behind them have lapsed, and the binaries keep shipping anyway. The most striking case is a single leaf certificate (serial 03 A9 18 8A A5 10 C0 F8 34 34 26 BF), issued to WEILAI NETWORK TECHNOLOGY under a GlobalSign GCC R45 EV CodeSigning chain, that signs three…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence