C&CMembers
C&C

Bright Data-Signed EarnApp Loader Unchanged as 66 New Domains Surround It

The same four DigiCert-signed EarnApp/net_updater binaries tied to a PBot stealer persist untouched from the prior snapshot, but this update adds 66 new domains and 19 new IPs against just 9 new file hashes. Two registrar cohorts and two certificate-issuer cohorts now bind dozens of previously unrelated-looking domains into the same picture.

Aug 11, 2026, 14:48 (UTC+9)Last seenAug 11, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC204MITRE2

The malicious file cluster that CTX Team first catalogued around a Bright Data Ltd-signed EarnApp installer has not moved: the same four binaries, the same DigiCert Trusted G4 Code Signing chain, the same detection spread running from 9 of 75 engines to 24 of 76. What has moved, sharply, is everything sitting around it. This snapshot adds 66 new domains and 19 new IPs against just 9 new file hashes — an order of magnitude more growth in registration and certificate infrastructure than in…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence