APTMembers
APT

Same Signer, Split Verdict: EarnApp Installer Hides a Stealer

Three Windows installers branded as Bright Data's EarnApp SDK share an identical Bright Data Ltd/DigiCert signing chain, yet one build is sandbox-classified as the PBot stealer while its two signer-siblings return clean verdicts. The cluster is tagged APT28 in feed metadata, but the tradecraft — a signed PUP installer pivoting to credential theft atop a disposable DGA-style .cc hosting layer — doesn't match that actor's playbook.

Jul 25, 2026, 13:38 (UTC+9)Last seenJul 25, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC66MITRE7

Three Windows installers branded as Bright Data's EarnApp bandwidth-sharing SDK carry an identical Bright Data Ltd/DigiCert code-signing chain — the same signer, the same certificate-authority path, the same product story. Yet one of the three, a build called net_updater32.exe, is classified by sandbox analysis as a STEALER named PBot, while its two signer-siblings return clean verdicts.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence