
Valid Bright Data Signature Found on EarnApp Installers Flagged as PBot Stealer
Four Windows EarnApp/Bright SDK installers carry a fully valid Bright Data Ltd DigiCert code-signing chain across two separate certificate waves, yet two are sandbox-flagged as the PBot stealer family. The certificate was never revoked, meaning trust signal and malicious classification coexist on the same files.
Four Windows installers branded as EarnApp — the passive-income tool that pays users to resell idle bandwidth through Bright Data's proxy network — carry a fully valid Bright Data Ltd code-signing chain from DigiCert, and two of them are independently flagged by a sandbox as the "PBot" stealer family. That combination is the story here, not because a certificate was forged or revoked, but because it wasn't.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read