
APT28 Hides PBot Stealer Inside Validly Signed Bright Data SDK Binary
A campaign attributed to APT28 deploys a three-tier toolkit that pairs trojanised KMS activation software with a legitimately DigiCert-signed proxy agent concealing the PBot stealer. The validly signed Bright Data binary achieves an 8/76 AV detection rate despite sandbox classification as malicious, exploiting trust already extended to a commercial vendor's signing chain rather than forging or stealing a certificate.
A 12-megabyte Windows executable carrying a fully valid DigiCert code-signing certificate for "Bright Data Ltd" — a commercially distributed proxy and VPN software vendor — is circulating as the stealth layer of an espionage toolkit that CTX Team has attributed to APT28, the Russian state-aligned threat group also tracked under aliases including Fancy Bear, Forest Blizzard, and Sofacy.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read