logo

Hackers Exploiting PDF24 App to Deploy Stealthy PDFSIDER Backdoor

ID: 173134fc-b8b3-5b4a-a329-1ef2d0f2cae4

STIX ID: report--173134fc-b8b3-5b4a-a329-1ef2d0f2cae4

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-01-19

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**Executive Summary:** PDFSIDER is a stealthy backdoor discovered by Resecurity that abuses the legitimate PDF24 App through DLL side-loading (dropping cryptbase.dll beside PDF24.exe) to run in-memory, perform sandbox checks, use Botan/AES-256-GCM for encrypted communications, and exfiltrate stolen data via DNS (port 53); researchers link its tactics to APT activity (e.g., Mustang Panda) and note ransomware groups are adopting it as a delivery mechanism.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.