C&CMembers
C&C

Revoked Certs, Live Trojans: VPN Malware Signs On Anyway

A VPN trojan signed under a now-revoked GlobalSign EV certificate, a VPNMaster line running on an expired DigiCert signature, and a validly-signed Bright Data proxyware SDK are all still circulating — one Bright Data binary even triggered a stealer verdict despite its currently valid signature.

Sep 25, 2026, 06:46 (UTC+9)Last seenSep 25, 2026Severity100ByCTX TeamActorCactusCactus Ransomware GroupIOC37MITRE16

A revoked EV certificate does not usually stop working the moment a certificate authority pulls it — Windows still launches the binary, users still click through the warning dialog if one even appears, and the software keeps installing exactly as it did the day it was minted. That quiet mechanical fact is the throughline connecting three unrelated Windows codebases surfacing in the same indicator set: a VPN trojan signed by WEILAI NETWORK TECHNOLOGY CO., LIMITED whose GlobalSign EV certificate…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence