
Shared Self-Signed TLS Cert Links Bytedance, Zenlayer IPs to VPN Trojans
One decade-valid self-signed certificate turns up unmodified on two IPs in Bytedance's US block and two in Zenlayer's Philippines block, tying the pair of unrelated clouds into a single C2-shaped asset. Behind that infrastructure sits a WEILAI-signed WireVPN loader/DLL kept alive months after its certificate was revoked, a VPNMaster PUA, and a Bright Data-branded binary a sandbox confirms as a PBot stealer.
Four IP addresses that share nothing else in common are running the identical self-signed TLS certificate — two sitting inside Bytedance's US-registered network block, two inside Zenlayer's Philippines allocation on the other side of the Pacific. The certificate carries serial number 1acf3e37b37910d932ea64e6bb27615d6484c07d, with both issuer and subject fields recorded simply as "NONE," and it is valid from March 12, 2024 clear through March 10, 2034 — a ten-year span that is itself unusual for…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read