C&CMembers
C&C

A Bright Data Certificate Keeps Signing Off on Worse and Worse Verdicts

Five builds of net_updater.exe share a currently-valid Bright Data Ltd/DigiCert code-signing chain even as VirusTotal's popular-name labels drift from PUA to hacktool to adware and an internal sandbox names the payload a 50%-confidence 'PBot' stealer. The pattern suggests third-party repackaging of a legitimate proxy SDK rather than a breach of Bright Data's own signing infrastructure.

Aug 16, 2026, 22:50 (UTC+9)Last seenAug 16, 2026Severity100ByCTX TeamActorCactusCactus Ransomware GroupIOC117MITRE9

A commercial proxy-network SDK's own code-signing certificate is what is holding together five different builds of a Windows binary called net_updater.exe — and the security industry's read on those builds has drifted, release over release, from potentially-unwanted software toward hacktool and adware categorization while an internal sandbox verdict flags the payload outright as a credential-stealing tool.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence