logo

PDFSIDER Malware Actively Exploited to Evade Antivirus and EDR Defenses

ID: 9c01b0a6-fbfc-5985-b8ed-bfd0bb0f3c9c

STIX ID: report--9c01b0a6-fbfc-5985-b8ed-bfd0bb0f3c9c

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-19

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive Summary:** PDFSIDER is a sophisticated backdoor delivered via spear-phishing ZIPs that side-loads a malicious cryptbase.dll alongside a signed PDF24 executable to bypass EDR; it runs mainly in memory, implements AES-256-GCM AEAD for encrypted C2 over DNS (port 53), and contains sandbox/VM detection and other evasion techniques, with provided IOCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.