
Bright Data's EarnApp Signing Chain Split to Smuggle a Stealer
A trusted Bright Data Ltd code-signing chain for the EarnApp bandwidth-sharing client is being used across both a clean installer and a separately-signed variant that a sandbox flags as the PBot stealer. The upstream feed's APT28 attribution doesn't match the commodity-stealer, adware-adjacent technical evidence.
A Windows installer that presents itself as EarnApp — Bright Data Ltd's consumer bandwidth-sharing client — is circulating in at least three variants that all carry a valid Bright Data Ltd code-signing chain anchored to DigiCert. Two of those variants read clean or undetected. The third, a component named net_updater32.exe dropped inside the same Program Files\EarnApp path, is classified by the C2AE sandbox as a stealer, with the malware family tag PBot attached at 50% confidence.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read