
Bright Data's Own Code-Signing Cert Fronts PBot Stealer
A binary signed with Bright Data Ltd's genuine, unrevoked DigiCert certificate installs itself as a fake 'Bright VPN' or 'DriverHub' updater — but a sandbox verdict identifies it as PBot, a credential-and-data-theft stealer. The certificate, vendor, and underlying proxy SDK are all real; only the intent is not.
A binary carrying Bright Data Ltd's genuine DigiCert-issued code-signing certificate — valid, unrevoked, chained straight to DigiCert Trusted Root G4 — installs itself under program paths named "Bright VPN" and "DriverHub" as net_updater32.exe. A sandbox verdict names what's actually running behind that trusted signature: PBot, classified as a credential-and-data-theft stealer. The certificate is real. The vendor is real. The proxy SDK it claims to be is real.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read