logo

PDFSIDER Malware – Exploitation of DLL Side-Loading for AV and EDR Evasion

ID: ed488785-5016-546a-8161-b28f14f3675a

STIX ID: report--ed488785-5016-546a-8161-b28f14f3675a

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-01-20

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

**PDFSIDER malware uses DLL side‑loading (fake cryptbase.dll) delivered via spear‑phishing ZIPs containing a legitimate PDF24 executable to bypass AV/EDR and deploy an encrypted backdoor; investigators observed APT‑style techniques, anti‑VM checks, and active use by ransomware actors targeting organizations.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.