
Trojanised VPN Installer Weaponises Two Legitimate Code-Signing Chains
A WireVPN installer bearing a valid GlobalSign EV certificate drops kernel-level netfilter drivers and proxy binaries while a parallel strand hides a PBot credential stealer inside a legitimately DigiCert-signed Bright Data SDK component. The dual-legitimacy approach — abusing genuine trust chains from two separate certificate authorities — allowed both tooling strands to suppress endpoint alerts across a broad deployment window backed by 27 IPs and 94 domains.
A 14.5-megabyte NSIS self-extracting archive named WireVpn_v3.6.0.3-6872e76.exe has been circulating through a curated software-distribution channel labelled "TS Recommended Apps" — bearing a valid Extended Validation code-signing certificate from GlobalSign, issued to a Chinese-registered entity called WEILAI NETWORK TECHNOLOGY CO., LIMITED, and dropping kernel-level netfilter drivers alongside proxy and jumper binaries that collectively form an espionage-oriented command-and-control platform.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read