logo

You don’t find ManualFinder, ManualFinder finds you

ID: acacd51d-5867-550a-a3ce-76339f833f77

STIX ID: report--acacd51d-5867-550a-a3ce-76339f833f77

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2025-08-22

Date Updated: 2026-04-27

Author: Aaron Walton

...
...

Expel investigated a campaign distributing seemingly benign apps (ManualFinder, PDF Editor, AppSuite-PDF, OneStart) that act as decoys while installing malicious components: scheduled tasks launch temporary JavaScript via node.exe which downloads signed MSI/EXE installers (code-signed by suspicious companies) and can turn hosts into residential proxies; the report includes execution logs, IOCs (file hashes and domains), evidence of persistence and active network connections, and recommended remediation steps including blocking domains, removing scheduled tasks, and revoking certificates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.