logo

From PDFs to Payload: Bogus Adobe Acrobat Reader Installers Distribute Byakugan Malware

ID: 77a9aaa8-9a49-5d75-8a55-3ba78c4f016d

STIX ID: report--77a9aaa8-9a49-5d75-8a55-3ba78c4f016d

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-04-05

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Fortinet and AhnLab disclosures describe a campaign delivering a node.js-based multi-functional malware called Byakugan via fake Adobe Acrobat Reader installers in Portuguese; the dropper uses DLL hijacking and UAC bypass to load a malicious DLL that fetches the main payload. Byakugan is reported to establish persistence, monitor desktops (using OBS), capture screenshots, log keystrokes, enumerate and exfiltrate files, and download cryptocurrency miners; the report also highlights concurrent campaigns distributing the Rhadamanthys infostealer and the WikiLoader/WailingCrab malware via manipulated installers and fake sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.