logo

Attackers Are Weaponizing Foxit PDF Reader’s Reputation

ID: 28dde3e8-d52d-5eb5-89a7-bd97e53ea1c8

STIX ID: report--28dde3e8-d52d-5eb5-89a7-bd97e53ea1c8

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Ddos

...
...

G DATA warns of a global social-engineering campaign that impersonates Foxit installer files to execute malicious EXEs which deploy an MSI that silently installs UltraVNC. The dropper uses decoy content (a Danish passport image), hides components under C:\intel-GPU, creates firewall exceptions and persistence via gpu.txt, SilentRun.vbs, gpu.cmd and gpu.exe, providing attackers full remote access and file exfiltration; detections appeared in Germany, the US, the UK and Ukraine.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.