APTMembers
APT

Fake ChatGPT Installer Hides Proxy SDK Classified as PBot Stealer

Trojanized VPN installers branded as WireVPN and VPNMaster, delivered via an AI-lure domain impersonating ChatGPT, silently co-install a Dotfuscator-obfuscated Bright Data SDK that two sandboxes independently classified as a PBot stealer. The operation sustains itself by abusing expired Extended Validation code-signing certificates across three distinct legal entities, a technique that has evaded broad detection across nearly two years of observed builds.

Jun 5, 2026, 23:19 (UTC+9)Last seenJun 5, 2026Severity100ByCTX TeamActorSpace PiratesWebwormIOC174MITRE20

When a user downloads what appears to be a Windows client for ChatGPT from chatgpt-windows.top — a domain registered on 2025-06-03 and already flagging 13 of 91 engines on VirusTotal — they receive something considerably more complex than a VPN application. CTX Team's analysis of this campaign reveals a layered abuse chain in which trojanized VPN installers branded as WireVPN and VPNMaster silently co-install a Dotfuscator-obfuscated .NET component signed by Bright Data Ltd that two independent…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence