
Space Pirates Add Signed .NET Stealer to Trojanized-VPN Arsenal
A follow-up snapshot of the Space Pirates campaign reveals a third signed-binary abuse vector: a Dotfuscator-packed PBot stealer concealed inside a legitimately-signed commercial SDK binary. Eight new malicious files, 18 fresh IPs, and 26 new domains accompany the payload expansion, alongside a ChatGPT-themed lure and a Philippine residential proxy tier.
Since CTX Team's earlier coverage of this campaign, eight new malicious files and a complete refresh of 18 IP addresses and 26 domains have surfaced — but the most operationally significant development is not the scale of the infrastructure turnover. It is the addition of a third signed-binary abuse vector: a Dotfuscator-packed, encrypted .NET stealer classified as PBot, hidden inside a binary carrying a valid Bright Data Ltd code-signing certificate.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read