
Fake ChatGPT Installer Hides Proxy SDK Classified as PBot Stealer
Trojanized VPN installers branded as WireVPN and VPNMaster, delivered via an AI-lure domain impersonating ChatGPT, silently co-install a Dotfuscator-obfuscated Bright Data SDK that two sandboxes independently classified as a PBot stealer. The operation sustains itself by abusing expired Extended Validation code-signing certificates across three distinct legal entities, a technique that has evaded broad detection across nearly two years of observed builds.
When a user downloads what appears to be a Windows client for ChatGPT from chatgpt-windows.top — a domain registered on 2025-06-03 and already flagging 13 of 91 engines on VirusTotal — they receive something considerably more complex than a VPN application. CTX Team's analysis of this campaign reveals a layered abuse chain in which trojanized VPN installers branded as WireVPN and VPNMaster silently co-install a Dotfuscator-obfuscated .NET component signed by Bright Data Ltd that two independent…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read