logo

Infostealer Disguised as Adobe Reader Installer

ID: f1c880b3-4b30-52f7-b7ba-d6bfa9f7fb5b

STIX ID: report--f1c880b3-4b30-52f7-b7ba-d6bfa9f7fb5b

Feed Name: ASEC

Threat Score
70/100

Date Published: 2024-03-12

Date Updated: 2026-04-26

Author: ov5925

...
...

AhnLab ASEC identified an Infostealer campaign delivering a malicious executable (Reader_Install_Setup.exe) masquerading as an Adobe Reader installer; users are lured via a Portuguese PDF and a GitHub raw download link. The installer creates require.exe and a malicious BluetoothDiagnosticUtil.dll, then abuses msdt.exe to run sdiagnhost.exe which loads the malicious DLL (DLL hijacking) enabling a UAC bypass; require.exe contacts C2 servers (blamefade.com.br and thinkforce.com.br), creates a hidden chrome.exe that collects system and browser data, and adds files to Defender exclusions. The report includes MD5 hashes, detection names, behavior details, and IOCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.