Threat Actors Leveraging Foxit PDF Reader to Gain System Control and Steal Sensitive Data
ID: 5f75ac9d-91fd-598a-989a-54daa94a4eea
STIX ID: report--5f75ac9d-91fd-598a-989a-54daa94a4eea
Feed Name: cybersecurityNews.com
Threat Score
The report describes the ValleyRAT campaign that targets job seekers with fake recruitment archives containing a disguised Foxit executable which abuses DLL side-loading (msimg32.dll), a bundled Python environment, and shellcode to deploy a remote access trojan that persists via registry entries and steals browser credentials and other sensitive data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
