APTMembers
APT

Signed Bright Data Component Escalates From Trojan to Stealer

A binary called net_updater.exe, signed with a valid, unrevoked Bright Data/DigiCert Authenticode chain, moved through three builds from September 2025 to June 2026 while AV engines disagreed on its label — trojan, then PUA, then adware. A sandbox looked past all three labels and classified two of the three builds outright as the PBot stealer.

Aug 28, 2026, 23:11 (UTC+9)Last seenAug 29, 2026Severity100ByCTX TeamActorCactusCactus Ransomware GroupIOC52MITRE8

A binary called net_updater.exe, carrying a valid, unrevoked Authenticode chain issued to Bright Data Ltd through DigiCert's Trusted G4 code-signing program, has moved through three successive builds between September 2025 and June 2026 — and detection engines have not agreed on what to call it at any point along the way. The first build, submitted in September 2025 (ae182434d7a588ed1d73054394fca0d95d8ea8d1b2cdb51477351e7c1df0932d), drew the label trojan.luminati/brightdata from 21 of 76…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence