C&CMembers
C&C

Proxyware Signing Pipeline Stays Static Despite Infrastructure Churn

New indicators add 47 file hashes, 27 IPs and 28 domains to a proxyware/stealer cluster CTX Team has tracked before, but the same three code-signing chains keep getting re-stamped onto an unchanged builder output. Four of five Bright Data-signed samples still sandbox as a PBot-classified stealer.

Jul 19, 2026, 13:38 (UTC+9)Last seenJul 19, 2026Severity100ByCTX TeamActorSpace PiratesWebwormIOC194MITRE17

Forty-seven new file hashes, twenty-seven new IP addresses and twenty-eight new domains have surfaced around a proxyware-and-stealer distribution cluster CTX Team has been tracking — yet the tradecraft underneath hasn't moved an inch. The same three code-signing chains that anchored our earlier look at this operation — Bright Data Ltd, WEILAI NETWORK TECHNOLOGY CO., LIMITED, and INNOVATIVE CONNECTING PTE.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence