logo

New PDFSider Windows malware deployed on Fortune 100 firm's network

ID: 2ec7ea64-9214-5235-8872-9e5c62cc050b

STIX ID: report--2ec7ea64-9214-5235-8872-9e5c62cc050b

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-01-19

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

PDFSider is a stealthy Windows backdoor used in targeted intrusions against a Fortune 100 finance firm; attackers delivered it via spearphishing ZIPs containing a legitimately signed PDF24 Creator executable plus a malicious cryptbase.dll (DLL side‑loading), achieving in‑memory execution, DNS-based C2 and exfiltration, AES-256-GCM encrypted communications using Botan, and multiple anti-analysis checks, and it has been observed in Qilin-linked and other ransomware actor operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.