Byte Bandits: How Fake PDF Converters Are Stealing More Than Just Your Documents
ID: a73530ef-7b89-5ed7-8705-bb3db27dda7f
STIX ID: report--a73530ef-7b89-5ed7-8705-bb3db27dda7f
Feed Name: CloudSEK Blog
This report documents a social-engineered malware campaign that clones pdfcandy.com with fake converter sites (e.g., candyxpdf.com, candyconverterpdf.com) to prompt victims to run a PowerShell command that ultimately retrieves and executes ArechClient2 (SectopRAT) via a chained redirect to bind-new-connect.click and a hosted payload (adobe.zip -> audiobit.exe). It includes IOCs (domains, IP 172.86.115.43, file names, hashes), analysis of the multi-stage execution (PowerShell -> cmd.exe -> MSBuild.exe -> ArechClient2), and actionable defensive recommendations such as blocking malicious domains, using EDR, scanning downloads, and user awareness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
