
Four Signers, One Playbook: Stolen Certs Mask VPN Trojans
A CTX-tracked file set shows trojanized VPN and proxy utilities signed with valid EV/OV certificates from four separate companies — WEILAI NETWORK TECHNOLOGY, Bright Data, INNOVATIVE CONNECTING, and WPS SOFTWARE — still drawing double-digit AV detections. The shared build lineages and a templated fallback infrastructure cluster point to one commodity-tooling pipeline cycling through abused signing identities rather than four unrelated compromises.
A trojan-tagged VPN utility called upWire.exe carries a fully valid EV code-signing chain from WEILAI NETWORK TECHNOLOGY CO., LIMITED, chained through GlobalSign GCC R45 EV CodeSigning CA 2020 — and still draws 29 of 74 engine detections. That contradiction sits at the center of a file set CTX Team has been tracking: nine dossiers, at least four distinct commercial signing identities, and a consistent trick underneath all of them — wrap a PUA or trojan dropper in a legitimate-looking VPN,…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read