
Fake VPN Installers Share Packer Fingerprint, Revoked Certificate Reuse
Three unrelated Windows installers — a Viber-branded dropper and two Bright Data proxy-SDK builds — fire the same crowdsourced YARA rule despite different threat labels and signers. Nearby, a separate WireVPN file family shows an operator repeatedly re-signing binaries with an EV code-signing certificate its issuer had already revoked.
A metadata marker meant to track Adobe image assets — the kind of thing that normally shows up in a PDF or a photo editor — turns up instead inside three Windows installers that have nothing else in common on paper. One poses as a Viber setup file. Two are builds of Bright Data's legitimate residential-proxy SDK, sold commercially as net_updater.exe.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read