logo

Think Before You Click: EPI PDF’s Hidden Extras

ID: ed463fbf-8f6c-532f-9325-036bc7e4ddb0

STIX ID: report--ed463fbf-8f6c-532f-9325-036bc7e4ddb0

Feed Name: McAfee Labs Blog

Threat Score
40/100

Date Published: 2025-08-04

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee research identifies EPI PDF Editor as a deceptive installer that bundles a chromium-based browser (EPIbrowser) and imports browser settings by default, classifying it as a Potentially Unwanted Program (PUP); the report includes technical analysis (installer behavior, privacy-policy mismatch, install locations), screenshots, a prevalence heatmap showing high encounters (e.g., ~118,000 US McAfee device encounters), and IOCs including multiple MSI filenames and SHA256 c2d1ac2511eb2749cdc7ae889d484c246d3bd1e740725dc4dd2813c4b4d05c7b, plus user mitigation advice (custom install, trusted sources, check browser settings).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.