APTMembers
APT

Valid Code Signatures Mask PBot Stealer in VPN/Proxy Installers

A Windows installer branded as Bright Data's proxy SDK carries an unbroken DigiCert signing chain yet still returns a sandbox verdict naming the PBot stealer. Ten files across three signer identities — Bright Data, WEILAI/WireVPN, and Innovative Connecting/VPNMaster — show that valid signatures and malicious intent have become nearly unrelated questions in this corner of the proxyware market.

Aug 8, 2026, 19:30 (UTC+9)Last seenAug 8, 2026Severity100ByCTX TeamActorEmotet GroupTA542IOC112MITRE22

A Windows installer branded as Bright Data's residential-proxy SDK carries a complete, unbroken DigiCert code-signing chain — and still returns a sandbox verdict naming the PBot stealer classification. Across ten files reviewed by CTX Team, three separate code-signing identities — Bright Data Ltd, WEILAI NETWORK TECHNOLOGY CO., LIMITED, and INNOVATIVE CONNECTING PTE.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence