Researchers Uncover PDFSIDER Malware Built for Long-Term, Covert System Access
ID: e655c962-7773-553c-bd56-00506c14a0ef
STIX ID: report--e655c962-7773-553c-bd56-00506c14a0ef
Feed Name: Infosecurity Magazine (News)
Resecurity documented a targeted malware campaign dubbed PDFSIDER that achieves stealthy, long-term access by DLL side-loading a malicious cryptbase.dll alongside a signed PDF24 executable delivered via spear-phishing. PDFSIDER performs system fingerprinting, runs commands through cmd.exe, uses the Botan library with AES-256-GCM for in-memory encrypted C2, includes anti-VM and debugger checks, and exfiltrates data (notably via DNS on port 53), allowing persistent covert access while evading common AV/EDR controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
