C&CMembers
C&C

Salty Spider Pivots to Valid WPS Certificate for Near-Invisible Telecom Implant

Six trojanised VPN and proxy installers signed with expired EV certificates are circulating against telecommunications targets, but the campaign's most dangerous file is a freshly signed implant masquerading as a Kingsoft WPS Office component with a valid certificate and a 1-in-76 detection rate. The actor, attributed to Salty Spider, has demonstrated a measurable shift in operational maturity by acquiring a live, high-trust signing identity valid through October 2028.

Jun 1, 2026, 07:00 (UTC+9)Last seenJun 1, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC63MITRE13

Six Windows executables circulating as VPN and proxy clients are carrying code-signing certificates from two Singapore-registered entities — INNOVATIVE CONNECTING PTE. LIMITED and WEILAI NETWORK TECHNOLOGY CO., LIMITED — whose DigiCert and GlobalSign EV credentials expired in April 2026 yet continue to present intact Authenticode chains that most endpoint controls will not challenge.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence