
Same Signer, Split Verdict: EarnApp Installer Hides a Stealer
Three Windows installers branded as Bright Data's EarnApp SDK share an identical Bright Data Ltd/DigiCert signing chain, yet one build is sandbox-classified as the PBot stealer while its two signer-siblings return clean verdicts. The cluster is tagged APT28 in feed metadata, but the tradecraft — a signed PUP installer pivoting to credential theft atop a disposable DGA-style .cc hosting layer — doesn't match that actor's playbook.
Three Windows installers branded as Bright Data's EarnApp bandwidth-sharing SDK carry an identical Bright Data Ltd/DigiCert code-signing chain — the same signer, the same certificate-authority path, the same product story. Yet one of the three, a build called net_updater32.exe, is classified by sandbox analysis as a STEALER named PBot, while its two signer-siblings return clean verdicts.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read