FILEMembers
FILE

Bright Data's EarnApp Signing Chain Split to Smuggle a Stealer

A trusted Bright Data Ltd code-signing chain for the EarnApp bandwidth-sharing client is being used across both a clean installer and a separately-signed variant that a sandbox flags as the PBot stealer. The upstream feed's APT28 attribution doesn't match the commodity-stealer, adware-adjacent technical evidence.

Jul 21, 2026, 13:40 (UTC+9)Last seenJul 21, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC151MITRE4

A Windows installer that presents itself as EarnApp — Bright Data Ltd's consumer bandwidth-sharing client — is circulating in at least three variants that all carry a valid Bright Data Ltd code-signing chain anchored to DigiCert. Two of those variants read clean or undetected. The third, a component named net_updater32.exe dropped inside the same Program Files\EarnApp path, is classified by the C2AE sandbox as a stealer, with the malware family tag PBot attached at 50% confidence.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence