logo

Stealthy Ad-Based Malware Campaign Targets Windows Users via PUPs

ID: d8cf55f9-bed2-5048-a42a-01b17a102419

STIX ID: report--d8cf55f9-bed2-5048-a42a-01b17a102419

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-08-25

Date Updated: 2026-04-19

Author: Priya

...
...

Researchers at Expel uncovered an ad-driven malware campaign in which apparently legitimate productivity apps (e.g., ManualFinder, OneStart, AppSuite-PDF, PDF Editor) are distributed via deceptive landing pages and bundled MSI installers that silently deploy trojans. The malware achieves persistence through scheduled tasks and Node.js-executed JavaScript droppers in %TEMP%, abuses code-signing certificates from questionable entities, connects to known malicious domains (mka3e8.com), and in some cases converts victim machines into residential proxies; the report provides IoCs and hunting/mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.