
Signed Bright Data SDK Delivers PBot Stealer via Three-Layer Evasion Stack
A validly signed 9.27 MB Windows executable placed inside Bright VPN and DriverHub install directories is delivering a Dotfuscator-obfuscated stealer payload while routing C2 traffic to two aged Chinese domains. A 15-IP Huawei CDN certificate cohort spanning China Telecom, China Mobile, and China Unicom address space provides network-layer cover, suppressing detection across 51 of 76 AV engines.
A 9.27-megabyte Windows executable, validly signed under a live DigiCert code-signing chain issued to Bright Data Ltd, is circulating as a trojanised update component placed directly inside Bright VPN and DriverHub installation directories — a delivery mechanism that exploits the grey-area status of commercial proxy-network software to suppress detection across the majority of the antivirus industry.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read