logo

Foxit PDF Reader Flaw Exploited by Hackers to Deliver Diverse Malware Arsenal

ID: 7e3a9c82-f921-5f3a-8f36-acd612d7ef46

STIX ID: report--7e3a9c82-f921-5f3a-8f36-acd612d7ef46

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-05-20

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

**Executive summary**: Multiple threat actors, including the DoNot Team (APT-C-35), are exploiting a Foxit PDF Reader design flaw that uses misleading default 'OK/Open' dialogs to execute commands and download malware (RATs, stealers, miners); campaigns leverage Discord CDN, GitLab, Trello and social platforms to deliver weaponized PDFs for espionage, credential theft and crypto‑mining, and Foxit plans a fix in version 2024.3.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.