PDFSIDER Malware – Exploitation of DLL Side-Loading for AV and EDR Evasion
ID: ed488785-5016-546a-8161-b28f14f3675a
STIX ID: report--ed488785-5016-546a-8161-b28f14f3675a
Feed Name: Security Affairs
Threat Score
**PDFSIDER malware uses DLL side‑loading (fake cryptbase.dll) delivered via spear‑phishing ZIPs containing a legitimate PDF24 executable to bypass AV/EDR and deploy an encrypted backdoor; investigators observed APT‑style techniques, anti‑VM checks, and active use by ransomware actors targeting organizations.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
