
Signed Bright Data Component Escalates From Trojan to Stealer
A binary called net_updater.exe, signed with a valid, unrevoked Bright Data/DigiCert Authenticode chain, moved through three builds from September 2025 to June 2026 while AV engines disagreed on its label — trojan, then PUA, then adware. A sandbox looked past all three labels and classified two of the three builds outright as the PBot stealer.
A binary called net_updater.exe, carrying a valid, unrevoked Authenticode chain issued to Bright Data Ltd through DigiCert's Trusted G4 code-signing program, has moved through three successive builds between September 2025 and June 2026 — and detection engines have not agreed on what to call it at any point along the way. The first build, submitted in September 2025 (ae182434d7a588ed1d73054394fca0d95d8ea8d1b2cdb51477351e7c1df0932d), drew the label trojan.luminati/brightdata from 21 of 76…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read