New PDFSider Windows malware deployed on Fortune 100 firm's network
ID: 2ec7ea64-9214-5235-8872-9e5c62cc050b
STIX ID: report--2ec7ea64-9214-5235-8872-9e5c62cc050b
Feed Name: Bleeping Computer
PDFSider is a stealthy Windows backdoor used in targeted intrusions against a Fortune 100 finance firm; attackers delivered it via spearphishing ZIPs containing a legitimately signed PDF24 Creator executable plus a malicious cryptbase.dll (DLL side‑loading), achieving in‑memory execution, DNS-based C2 and exfiltration, AES-256-GCM encrypted communications using Botan, and multiple anti-analysis checks, and it has been observed in Qilin-linked and other ransomware actor operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
