APTMembers
APT

Broken 'Not Time Valid' Certificates Still Signing VPN Trojans

Two unrelated commercial code-signing chains — GlobalSign-issued to WEILAI NETWORK TECHNOLOGY and DigiCert-issued to INNOVATIVE CONNECTING — keep signing VPN/proxy-branded trojans despite leaf certificates flagged 'not time valid.' A third, validly Bright Data-signed proxy binary in the same set is sandboxed as a credential-stealing PBot, undercutting the feed's own Cactus ransomware/ramnit attribution.

Jul 28, 2026, 13:34 (UTC+9)Last seenJul 28, 2026Severity100ByCTX TeamActorCactusCactus Ransomware GroupIOC108MITRE18

Two unrelated commercial code-signing chains — one issued to WEILAI NETWORK TECHNOLOGY CO., LIMITED through GlobalSign's EV pipeline, the other to INNOVATIVE CONNECTING PTE. LIMITED through DigiCert — are each producing a small, active cluster of VPN- and proxy-branded trojans whose leaf certificates carry the identical defect: "This certificate or one of the certificates in the certificate chain is not time valid." Neither cluster has stopped signing because of it.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence