logo

Byte Bandits: How Fake PDF Converters Are Stealing More Than Just Your Documents

ID: a73530ef-7b89-5ed7-8705-bb3db27dda7f

STIX ID: report--a73530ef-7b89-5ed7-8705-bb3db27dda7f

Feed Name: CloudSEK Blog

Threat Score
75/100

Date Published: 2025-04-15

Date Updated: 2026-04-27

...
...

This report documents a social-engineered malware campaign that clones pdfcandy.com with fake converter sites (e.g., candyxpdf.com, candyconverterpdf.com) to prompt victims to run a PowerShell command that ultimately retrieves and executes ArechClient2 (SectopRAT) via a chained redirect to bind-new-connect.click and a hosted payload (adobe.zip -> audiobit.exe). It includes IOCs (domains, IP 172.86.115.43, file names, hashes), analysis of the multi-stage execution (PowerShell -> cmd.exe -> MSBuild.exe -> ArechClient2), and actionable defensive recommendations such as blocking malicious domains, using EDR, scanning downloads, and user awareness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.