C&CMembers
C&C

Signed Bright Data SDK Delivers PBot Stealer via Three-Layer Evasion Stack

A validly signed 9.27 MB Windows executable placed inside Bright VPN and DriverHub install directories is delivering a Dotfuscator-obfuscated stealer payload while routing C2 traffic to two aged Chinese domains. A 15-IP Huawei CDN certificate cohort spanning China Telecom, China Mobile, and China Unicom address space provides network-layer cover, suppressing detection across 51 of 76 AV engines.

May 31, 2026, 09:10 (UTC+9)Last seenMay 31, 2026Severity100ByCTX TeamIOC60

A 9.27-megabyte Windows executable, validly signed under a live DigiCert code-signing chain issued to Bright Data Ltd, is circulating as a trojanised update component placed directly inside Bright VPN and DriverHub installation directories — a delivery mechanism that exploits the grey-area status of commercial proxy-network software to suppress detection across the majority of the antivirus industry.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence