PDFSIDER Malware Actively Exploited to Evade Antivirus and EDR Defenses
ID: 9c01b0a6-fbfc-5985-b8ed-bfd0bb0f3c9c
STIX ID: report--9c01b0a6-fbfc-5985-b8ed-bfd0bb0f3c9c
Feed Name: GBHackers
Threat Score
**Executive Summary:** PDFSIDER is a sophisticated backdoor delivered via spear-phishing ZIPs that side-loads a malicious cryptbase.dll alongside a signed PDF24 executable to bypass EDR; it runs mainly in memory, implements AES-256-GCM AEAD for encrypted C2 over DNS (port 53), and contains sandbox/VM detection and other evasion techniques, with provided IOCs for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
