APTMembers
APT

Expired Certificates Keep Signing Trojanized VPN Installers

Two code-signing identities — WEILAI NETWORK TECHNOLOGY and INNOVATIVE CONNECTING PTE — keep issuing new VPN/proxy installer builds despite certificate chains flagged 'not time valid' for months. The same reuse discipline shows up in hosting, with a single Akamai-branded TLS certificate serial recycled across three unrelated Philippine ASNs.

Aug 2, 2026, 05:31 (UTC+9)Last seenAug 2, 2026Severity100ByCTX TeamActorUAC-0063TAG-110IOC103MITRE22

The most durable piece of tradecraft in this campaign isn't a novel loader or a clever injection technique — it's a pair of Authenticode certificates that have been technically invalid for months and are still being used to sign new builds. Two code-signing identities, WEILAI NETWORK TECHNOLOGY CO., LIMITED (chained through GlobalSign GCC R45 EV CodeSigning CA 2020) and INNOVATIVE CONNECTING PTE.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence