C&CMembers
C&C

APT28 Hides PBot Stealer Inside Validly Signed Bright Data SDK Binary

A campaign attributed to APT28 deploys a three-tier toolkit that pairs trojanised KMS activation software with a legitimately DigiCert-signed proxy agent concealing the PBot stealer. The validly signed Bright Data binary achieves an 8/76 AV detection rate despite sandbox classification as malicious, exploiting trust already extended to a commercial vendor's signing chain rather than forging or stealing a certificate.

Jun 6, 2026, 11:40 (UTC+9)Last seenJun 6, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC14MITRE11

A 12-megabyte Windows executable carrying a fully valid DigiCert code-signing certificate for "Bright Data Ltd" — a commercially distributed proxy and VPN software vendor — is circulating as the stealth layer of an espionage toolkit that CTX Team has attributed to APT28, the Russian state-aligned threat group also tracked under aliases including Fancy Bear, Forest Blizzard, and Sofacy.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence