
A Bright Data Certificate Keeps Signing Off on Worse and Worse Verdicts
Five builds of net_updater.exe share a currently-valid Bright Data Ltd/DigiCert code-signing chain even as VirusTotal's popular-name labels drift from PUA to hacktool to adware and an internal sandbox names the payload a 50%-confidence 'PBot' stealer. The pattern suggests third-party repackaging of a legitimate proxy SDK rather than a breach of Bright Data's own signing infrastructure.
A commercial proxy-network SDK's own code-signing certificate is what is holding together five different builds of a Windows binary called net_updater.exe — and the security industry's read on those builds has drifted, release over release, from potentially-unwanted software toward hacktool and adware categorization while an internal sandbox verdict flags the payload outright as a credential-stealing tool.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read