
Fake VPN Trojans Keep Two Invalid EV Certs Alive as Hosts Vanish
Seven Windows binaries posing as VPN and proxy tools still sign under the same two Extended Validation code-signing identities, even as 22 domains, six IPs and three URLs tied to the campaign have disappeared. Both leaf certificates fail VirusTotal's chain-validity check yet still display as fully "Signed" on the endpoint.
Seven Windows binaries circulating as fake VPN and proxy utilities are still riding on the same two Extended Validation code-signing identities they carried the last time CTX Team looked at this cluster — even though 22 domains, six IPs and three URLs have vanished from the campaign's front-end footprint since then. The payload side hasn't moved an inch: every signed sample in both families carries a leaf certificate that VirusTotal's chain validator flags as "not time valid," and every one of…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read