
PBot Stealer Gets 64-Bit Rebuild, Drops to 9/76 Detections
A freshly compiled 64-bit net_updater variant, first seen May 19 2026, marks the first architectural shift in the VPN-lure PBot stealer campaign. The new sample carries a unique import-table hash breaking from its 32-bit predecessors, yet retains the same signing identity and Dotfuscator obfuscation pipeline that has tracked the family for ten months.
Since CTX Team's earlier coverage of this VPN-lure PBot stealer campaign, the most operationally significant development is not the expansion of the domain or IP set — though both have grown substantially — but a single freshly compiled binary that signals the operator is actively retooling the payload build pipeline rather than coasting on existing artifacts.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read