C&CMembers
C&C

Bright Data-Signed Proxy SDK Joins Signed VPN-Trojan Pipeline

A signed-installer campaign already known for the WireVPN and VPNMaster trojan families has added a new payload: two Bright Data-certified binaries flagged as a hacktool/adware proxy-reseller SDK. The core delivery mechanism — two revoked-trust signer chains — hasn't changed; what's new is a second monetization model layered on top of it.

Sep 16, 2026, 14:31 (UTC+9)Last seenSep 16, 2026Severity100ByCTX TeamActorCactusCactus Ransomware GroupIOC70MITRE19

Two freshly signed executables — a proxy updater called net_updater.exe and a companion labelled idle_report.exe (2b7c3cdca1fd951c…), both carrying a Bright Data Ltd certificate and both first submitted just seventeen days before this review — have surfaced inside a signed-installer distribution pipeline CTX Team has continued to track.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence