Hackers Exploiting PDF24 App to Deploy Stealthy PDFSIDER Backdoor
ID: 173134fc-b8b3-5b4a-a329-1ef2d0f2cae4
STIX ID: report--173134fc-b8b3-5b4a-a329-1ef2d0f2cae4
Feed Name: HackRead
Threat Score
**Executive Summary:** PDFSIDER is a stealthy backdoor discovered by Resecurity that abuses the legitimate PDF24 App through DLL side-loading (dropping cryptbase.dll beside PDF24.exe) to run in-memory, perform sandbox checks, use Botan/AES-256-GCM for encrypted communications, and exfiltrate stolen data via DNS (port 53); researchers link its tactics to APT activity (e.g., Mustang Panda) and note ransomware groups are adopting it as a delivery mechanism.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
