C&CMembers
C&C

Fake Bright Data Signature Cloaks PBot Stealer in Update Lure

A binary signed with a valid, unexpired Bright Data Ltd code-signing certificate poses as a VPN/driver-update tool but drops a packed .NET payload a sandbox unanimously flags as the PBot stealer. The finding is a single well-verified sample inside a mostly-empty 49-file, four-IP, ten-domain record tagged to transportation.

Jul 29, 2026, 13:43 (UTC+9)Last seenJul 29, 2026Severity100ByCTX TeamIOC63MITRE6

A Bright Data Ltd code-signing certificate — issued through DigiCert's Trusted G4 chain and still inside its 2025~2027 validity window — is authenticating a binary that a sandbox flags outright as the PBot stealer. The file, shipped internally as net_updater.exe, drops into install paths named "DriverHub" and "Bright VPN" [T1036.005], borrowing the visual language of a legitimate residential-proxy SDK to get past the trust checks that a valid signature is supposed to guarantee [T1553.002].

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence