logo

MSUpdater Trojan And Link To Targeted Attacks

ID: e285cc99-6860-59a5-8841-be7fa70df906

STIX ID: report--e285cc99-6860-59a5-8841-be7fa70df906

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This joint Zscaler and Seculert report describes a targeted campaign delivering a VM-aware remote access Trojan via malicious PDFs that exploit an Adobe vulnerability (CVE-2010-2883). The malware decrypts functionality at runtime, communicates with command-and-control servers over encoded HTTP using Microsoft Update-like filenames and paths to evade detection, and includes indicators and TTPs useful for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.