PDFSIDER Discovered: New APT Malware Uses DLL Side-Loading to Evade Detection
ID: cd05b007-f05c-5cc8-a66c-255f926ad48e
STIX ID: report--cd05b007-f05c-5cc8-a66c-255f926ad48e
Feed Name: securityonline.info
Threat Score
PDFSIDER is a newly identified malware variant distributed via malicious ZIP archives that abuses DLL side-loading (using a fake cryptbase.dll) to hijack trusted applications and deploy a covert backdoor. The payload embeds a Botan cryptographic library configured for AES-256-GCM to provide encrypted C2 and an interactive hidden shell, includes anti-VM checks, and exemplifies APT-like living-off-the-land tradecraft to evade AV/EDR and network analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
