C&CMembers
C&C

Dual-Cert Trojan VPN Pipeline Targets Food and Beverage Sector

Two shell entities holding EV and OV code-signing certificates from DigiCert and GlobalSign are distributing trojanized VPN software that evades sandbox analysis while establishing proxy-chain C2 infrastructure anchored in a Chengdu internet data centre. The campaign, tracked as CTXv7h57gk27a, pairs short-lived DGA-pattern domains with stable egress IPs to suppress detection across major antivirus engines.

May 26, 2026, 21:02 (UTC+9)Last seenMay 26, 2026Severity100ByCTX TeamActorBariumWicked SpiderIOC54MITRE7

Five Windows executables are circulating as components of a legitimate-looking VPN product — each carrying a valid-chain code-signing certificate issued to one of two shell entities, "INNOVATIVE CONNECTING PTE. LIMITED" and "WEILAI NETWORK TECHNOLOGY CO., LIMITED" — while quietly establishing proxy-chain command-and-control infrastructure anchored in a Chengdu internet data centre.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence