C&CMembers
C&C

Valid Bright Data Certificate Signs a Sandboxed PBot Stealer

A currently valid, unrevoked Bright Data Ltd code-signing certificate covers a residential-proxy SDK that one sandbox run flagged as the stealer family PBot — while two sibling toolchains riding already-revoked or expired certificates produced cleaner verdicts. The inversion between certificate trust and actual behavior is the through-line across this ten-file set.

Sep 9, 2026, 22:36 (UTC+9)Last seenSep 9, 2026Severity100ByCTX TeamIOC41MITRE21

A residential-proxy SDK carrying a currently valid Bright Data Ltd code-signing certificate has been sandboxed with a malicious verdict naming the stealer family PBot — the freshest and most unsettling signal in a ten-file set that otherwise reads like ordinary VPN and proxy bloatware. Two other toolchains in the same batch ride certificates that have already been revoked or expired, yet neither produces a cleaner behavioural outcome than the one still in good standing.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence