C&CMembers
C&C

Signed and Trusted: Two Malware Families Ride Valid Certs

A Bright Data-signed 'Bright SDK' installer was flagged as the PBot stealer despite a fully valid DigiCert signing chain, while a separate VPN-trojan family keeps circulating a full year after its EV certificate was revoked. Both clusters share templated hosting infrastructure, including an identical self-signed TLS certificate deployed across unrelated Bytedance and Zenlayer netblocks.

Sep 15, 2026, 14:49 (UTC+9)Last seenSep 15, 2026Severity100ByCTX TeamActorCactusCactus Ransomware GroupIOC79MITRE18

Four executables signed with a fully valid Bright Data Ltd certificate — the kind of code-signing chain that is supposed to reassure a user they are installing legitimate software — carry threat labels ranging from hacktool and PUA to adware and downloader, and one of them was flagged outright by a sandbox as a stealer. The file, an 11.5MB installer named net_updater.exe (909f62b450…), returned a malicious verdict with the classification "STEALER" and the family name "PBot," despite presenting…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence