
Valid Code Signatures Mask PBot Stealer in VPN/Proxy Installers
A Windows installer branded as Bright Data's proxy SDK carries an unbroken DigiCert signing chain yet still returns a sandbox verdict naming the PBot stealer. Ten files across three signer identities — Bright Data, WEILAI/WireVPN, and Innovative Connecting/VPNMaster — show that valid signatures and malicious intent have become nearly unrelated questions in this corner of the proxyware market.
A Windows installer branded as Bright Data's residential-proxy SDK carries a complete, unbroken DigiCert code-signing chain — and still returns a sandbox verdict naming the PBot stealer classification. Across ten files reviewed by CTX Team, three separate code-signing identities — Bright Data Ltd, WEILAI NETWORK TECHNOLOGY CO., LIMITED, and INNOVATIVE CONNECTING PTE.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read