
Dual-Cert Trojan VPN Pipeline Targets Food and Beverage Sector
Two shell entities holding EV and OV code-signing certificates from DigiCert and GlobalSign are distributing trojanized VPN software that evades sandbox analysis while establishing proxy-chain C2 infrastructure anchored in a Chengdu internet data centre. The campaign, tracked as CTXv7h57gk27a, pairs short-lived DGA-pattern domains with stable egress IPs to suppress detection across major antivirus engines.
Five Windows executables are circulating as components of a legitimate-looking VPN product — each carrying a valid-chain code-signing certificate issued to one of two shell entities, "INNOVATIVE CONNECTING PTE. LIMITED" and "WEILAI NETWORK TECHNOLOGY CO., LIMITED" — while quietly establishing proxy-chain command-and-control infrastructure anchored in a Chengdu internet data centre.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read