
Expired Certificates Keep Signing Trojanized VPN Installers
Two code-signing identities — WEILAI NETWORK TECHNOLOGY and INNOVATIVE CONNECTING PTE — keep issuing new VPN/proxy installer builds despite certificate chains flagged 'not time valid' for months. The same reuse discipline shows up in hosting, with a single Akamai-branded TLS certificate serial recycled across three unrelated Philippine ASNs.
The most durable piece of tradecraft in this campaign isn't a novel loader or a clever injection technique — it's a pair of Authenticode certificates that have been technically invalid for months and are still being used to sign new builds. Two code-signing identities, WEILAI NETWORK TECHNOLOGY CO., LIMITED (chained through GlobalSign GCC R45 EV CodeSigning CA 2020) and INNOVATIVE CONNECTING PTE.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read