
Proxyware Family Resigned Four Times to Dodge Detection
A 90-file cluster shows a proxyware binary rebuilt and re-signed four times under fresh Bright Data Ltd certificates between July 2025 and March 2026, with detection dropping from 22/75 to 8/76 engines. Three of the four builds carry sandbox verdicts naming a 'PBot' stealer beneath the legitimate-looking signature.
A ninety-file cluster now under review shows a builder rebuilding and re-signing the same proxyware binary at least four times between July 2025 and March 2026, watching its own detection ratio slide from 22 out of 75 engines down to 8 out of 76 as each new build shipped. The four samples — carrying the meaningful name net_updater.exe and the internal product tag "Bright SDK" — share a single import-table hash, a4383347bad6319cb6d1cefa3c6272d8, and near-identical vhash fingerprints, yet each…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read