FILEMembers
FILE

Four Signers, One Playbook: Stolen Certs Mask VPN Trojans

A CTX-tracked file set shows trojanized VPN and proxy utilities signed with valid EV/OV certificates from four separate companies — WEILAI NETWORK TECHNOLOGY, Bright Data, INNOVATIVE CONNECTING, and WPS SOFTWARE — still drawing double-digit AV detections. The shared build lineages and a templated fallback infrastructure cluster point to one commodity-tooling pipeline cycling through abused signing identities rather than four unrelated compromises.

Jul 15, 2026, 21:56 (UTC+9)Last seenJul 15, 2026Severity100ByCTX TeamActorCactusCactus Ransomware GroupIOC99MITRE34

A trojan-tagged VPN utility called upWire.exe carries a fully valid EV code-signing chain from WEILAI NETWORK TECHNOLOGY CO., LIMITED, chained through GlobalSign GCC R45 EV CodeSigning CA 2020 — and still draws 29 of 74 engine detections. That contradiction sits at the center of a file set CTX Team has been tracking: nine dossiers, at least four distinct commercial signing identities, and a consistent trick underneath all of them — wrap a PUA or trojan dropper in a legitimate-looking VPN,…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence