#PDFSIDER
Ransomware attackers targeting a Fortune 100 company in the finance sector used a new malware strain, dubbed PDFSider, to deliver malicious payloads on Windows systems.
New PDFSider Windows malware deployed on Fortune 100 firm's network
Ransomware attackers targeting a Fortune 100 company in the finance sector used a new malware strain, dubbed PDFSider, to deliver malicious payloads on Windows systems.
www.bleepingcomputer.com
January 19, 2026 at 9:00 PM
-Malware reports on MonetaStealer, SolyxImmortal, TamperedChef, Remcos RAT
-New PDFSIDER APT malware
-APT-C-06 (DarkHotel) adopts USB malware
-CodeBreach vuln impacts AWS
-Cisco patches zero-day
-New 0-click Android exploit
-New FortiSIEM attacks
-CrowdStrike wins shareholder lawsuit
January 19, 2026 at 12:01 AM
BleepingComputer - Article
"New PDFSider Windows malware deployed on Fortune 100 firm's network"...

www.bleepingcomputer.com/news/securit...

==========================
#librecanada #linux #opensource
New PDFSider Windows malware deployed on Fortune 100 firm's network
Ransomware attackers targeting a Fortune 100 company in the finance sector used a new malware strain, dubbed PDFSider, to deliver malicious payloads on Windows systems.
www.bleepingcomputer.com
January 29, 2026 at 1:58 PM
Resecurity has spotted a new backdoor named PDFSIDER.

The company believes the malware has been created by an APT group, but no other details are provided except that the malware was deployed in a failed attack at a Fortune 100 company.

www.resecurity.com/blog/article...
January 18, 2026 at 6:57 PM
January 21, 2026 at 7:01 PM
Sicherheitsforscher entdecken neue Malware PDFSider. Die Schadsoftware kombiniert technische Raffinesse mit #SocialEngineering für langfristigen Systemzugriff.
PDFSider: Malware sucht langfristigen Zugriff auf Windows-Systeme
winfuture.de
January 20, 2026 at 11:28 AM
PDFSider: Novo malware usa software de PDF para atacar gigantes financeiros

#malware #pdf #software
PDFSider: Novo malware usa software de PDF para atacar gigantes financeiros
tugatech.com.pt
January 19, 2026 at 9:48 PM
📢⚠️ Hackers are exploiting the #PDF24 app to deliver the new PDFSIDER backdoor via DLL sideloading and phishing, giving them remote access and data theft capabilities.

Read: hackread.com/hackers-expl...

#PDFSIDER #Malware #Infosec #Cybersecurity #Phishing
Hackers Exploiting PDF24 App to Deploy Stealthy PDFSIDER Backdoor
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
January 19, 2026 at 12:32 PM
🔴 Découverte de PDFSider

Une entreprise du Fortune 100 (secteur finance) a été ciblée par ce nouveau malware, utilisé comme porte dérobée par des groupes de ransomware comme Qilin.

Retrouvez mon article à ce sujet 👇
- www.it-connect.fr/le-malware-p...

#infosec #cybersecurite #windows
January 21, 2026 at 7:01 AM
Notícia da SecurityWeek

"APT-Grade PDFSider Malware Used by Ransomware Groups" #bolhasec
APT-Grade PDFSider Malware Used by Ransomware Groups
Attacks linked to APT and ransomware groups are relying on DLL sideloading for code execution instead of exploit-based initial access.
www.securityweek.com
February 15, 2026 at 10:30 PM
Notícia da BleepingComputer

"New PDFSider Windows malware deployed on Fortune 100 firm's network" #bolhasec
New PDFSider Windows malware deployed on Fortune 100 firm's network
Ransomware attackers targeting a Fortune 100 company in the finance sector used a new malware strain, dubbed PDFSider, to deliver malicious payloads on Windows systems.
www.bleepingcomputer.com
January 27, 2026 at 2:30 PM
📰 Malware Baru PDFSider Ditemukan Menyusup ke Jaringan Perusahaan Fortune 100

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/01/20/malware-pdfsider-windows-fortune-100/

#cyb
er#cybersecuritya#keamananr#sibera#malwareo#ransomwarer#spearh#phishingo#windowsa#malware
January 20, 2026 at 5:25 AM
PDFSIDER: Un falso PDF sta aprendo backdoor invisibili: cosa c’è dietro la nuova minaccia

📌 Link all'articolo : www.redhotcyber.com/post/pdf...

#redhotcyber #news #malware #cybersecurity #hacking #backdoor #cryptbase #sicurezzainformatica
January 20, 2026 at 2:39 PM
Fake Malwarebytes ZIPs, Signed VS Code Stealers, and PDF Backdoors: How Trust, Not Zero-Days, Is Breaching Enterprises
### TL;DR * Malwarebytes Campaign Tricks Users into Downloading Fake Software via DLL Sideloading, Stealing Crypto and Credentials * Cybercriminals Exploit Visual Studio Code Marketplace with Evelyn Stealer Extension to Steal Source Code and Cloud Tokens * Microsoft Enforces Intune Security Policies, Blocking Business Email Access for Non-Compliant Apps Since Jan 19, 2026 * PDFSIDER APT Malware Uses DLL Side-Loading and DNS Exfiltration to Bypass Antivirus in Fortune 100 Cyberattack * * * ## 🚨 Why Are People Still Downloading Fake Malwarebytes From GitHub? > Fake Malwarebytes ZIP? No, it’s not a phishing email. It’s a ZIP. A DLL. A wallet.dat. And 0.04 BTC gone. 🚨 This isn’t zero-day—it’s zero-brain. Users unzip. Windows loads. Crypto vanishes. Block SHA-256: 4acaac53... Enforce WDAC. MFA. Hardware wallets. #Cybersecurity #Malwarebytes #DLLSideloading #CryptoScam Let’s be honest: if you’re downloading a ZIP called `malwarebytes-windows-github-io-X.X.x.zip`, you’re not a cybersecurity professional—you’re a human-shaped vulnerability. This campaign doesn’t exploit zero-days. It exploits _trust_ and _click-happy curiosity_. The attacker didn’t hack Malwarebytes. They didn’t even need to. They just copied the name, dropped a malicious `CoreMessaging.dll` beside the _real_ `CoreMessaging.exe`, and waited for someone to unzip and run it. Windows loader? It loads the first DLL it finds. The malicious one. Boom. Credential harvest. Wallet.dat exfiltration. 0.04 BTC gone. Per victim. Repeatedly. This isn’t advanced. It’s _efficient_. And it works because: * People think "GitHub" means "open source" and therefore "safe." * They don’t check publisher metadata (spoofed: "Eosinophil LLC"—a real word, zero credibility). * They ignore that Malwarebytes, Inc. doesn’t distribute installers via GitHub. The IOCs? Straightforward: * SHA-256: `4acaac53c8340a8c236c91e68244e6cb` * C2: `185.62.73.44:443` | `malwarebytes-download[.]net` * Strings: `15Mmm95ml1RbfjH1VUyelYFCf`, `2dlSKEtPzvo1mHDN4FYgv` * File: `CoreMessaging.dll` _not_ signed by Microsoft And yes—they’re already preparing v2. Expect signed DLLs soon. Code-signing certs are cheap. WDAC? AppLocker? If you’re not whitelisting Malwarebytes binaries by publisher ("Malwarebytes, Inc.") and blocking unsigned DLLs in app directories, you’re just delaying the inevitable. Bottom line: Your users aren’t stupid. They’re just tired. And tired people click "Extract All." **Actionables:** * Block the SHA-256 on every gateway. * Enforce WDAC/AppLocker rules that _require_ Microsoft-signed DLLs in Malwarebytes directories. * Send users a screenshot of the _real_ download page: `malwarebytes.com` — not GitHub. Not MediaFire. Not Mega. * Enforce MFA. Everywhere. * If you still let people store crypto on software wallets? You’re the problem. This isn’t a hack. It’s a mirror. We built the system. They just walked in. * * * ## 🤦‍♂️ Why Are Developers Still Installing Random Extensions From Microsoft’s Own Store? > You installed an extension from the VS Code Marketplace. It had a Microsoft signature. It looked legit. Then it stole your AWS tokens, Wi-Fi passwords, and 17 private repos. 🤦‍♂️ This isn’t hacking. It’s laziness. #Cybersecurity #VSCode #SupplyChainAttack #DevSecOps Let’s be honest: if you’ve ever installed a VS Code extension because it had ‘10K downloads’ and a star rating that looked like it was generated by a bot named ‘Bob’, you’re part of the problem. The Evelyn Stealer extension—yes, that’s its real name, and no, it’s not a typo—was hosted on the official Visual Studio Code Marketplace. It carried a Microsoft signature. It looked legitimate. It even updated quietly, like a good little citizen. And then, while you were busy debugging a TypeScript error, it dropped a forged `Lightshot.dll` into your `.vscode/extensions` folder, loaded it via Windows side-loading, and quietly harvested your AWS IAM tokens, Azure AD credentials, Wi-Fi passwords, and the 17 GitHub repos you didn’t want anyone to see. This isn’t novel. It’s a playbook: exploit trust. Abuse signed binaries. Exfiltrate via FTP because someone forgot to block port 21 in 2018. Repeat across Chrome, VS Code, JetBrains, and Eclipse. Microsoft will now ‘tighten vetting’. EDR vendors will add ‘side-load in .vscode’ detection rules. You’ll get a mandatory training module titled ‘Don’t Be the Weakest Link (Again)’. And in 30 days, attackers will move from FTP to HTTPS—because even criminals know that TLS is the new silent killer. Here’s what actually works: * **Whitelist extensions**. If it’s not on your org’s approved list, it doesn’t install. Period. * **Enforce WDAC policies**. Block unsigned DLLs in `%USERPROFILE%\.vscode\extensions`. If Lightshot.exe loads something that isn’t Microsoft-signed, kill it. * **Monitor outbound`STOR` from Code.exe**. If `eveline.exe` pops up in your SIEM, you’ve already lost. Detect it before the ZIP uploads. * **Rotate cloud tokens daily**. If your AWS key is older than your last team-building retreat, you’re begging to be breached. * **Scan new marketplace uploads automatically**. Use `vsx-scanner`. Or pay for a tool. Or keep pretending ‘reviews’ mean security. The real tragedy? This attack didn’t exploit a zero-day. It exploited your muscle memory. You clicked ‘Install’ because the UI looked right. So next time you install an extension? Ask yourself: Who is Bob? And why does he have access to your cloud? * * * ## 💀 Microsoft Just Killed Your Email App—And You Probably Deserved It > Microsoft blocked business email for non-compliant apps on Jan 19, 2026. Your Outlook? Dead. Your Windows 11? Broken. Your help desk? Crying. SDK ≥2025.12 or App Wrapper v3. No exceptions. #Cybersecurity #MicrosoftIntune #ITPro #TechSarcasm On January 19, 2026, Microsoft Intune didn’t just update a policy. It declared war on legacy apps. If your Outlook, Teams, or OneDrive client doesn’t have SDK ≥2025.12 or isn’t wrapped in Intune-App-Wrapper v3? Goodbye, email. No warnings. No ‘maybe next time.’ Just a hard block at the network edge. The first 24 hours? A 68% spike in help-desk tickets. 1,200 users. 0.9% of a typical 130k-tenant. But here’s the twist: that spike didn’t come alone. It arrived with KB5073724—the January Patch Tuesday update that broke Windows 11’s hibernation, nuked Remote Desktop auth, and added 45% more tickets. So yes, your email is gone. And your computer won’t wake up. And you can’t remote in to fix it. Happy Monday. Compliance isn’t optional. It’s mandatory. Two requirements: SDK 2025.12 or App Wrapper v3. Both must be present. Device must be enrolled. And yes, Microsoft is logging every denied request under Event ID 4625 + IntuneDeviceManagement logs. Your IT team is now a detective agency, sifting through logs while answering Slack messages from the CFO who just screamed, “I can’t open my email!” Mitigation? Three words: recompile, wrap, communicate. 1. Rebuild legacy apps with SDK ≥2025.12. Fixes ~90% of issues. 2. Deploy Intune App Wrapper v3. It’s not magic—it’s a code layer that tells Intune, “I’m clean.” 3. Tell users the webmail URL: outlook.office.com. Yes, really. People still use it. And they’ll thank you. Pro tip: Run `Get-IntuneManagedDevice | Where {$_.AppVersion -lt "2025.12"}`. It’s not glamorous. But it’s the only thing standing between chaos and a spreadsheet. Meanwhile, Microsoft’s Secure Score? Up 12 points for the prepared. Down 5 for the procrastinators. And on March 1, 2026, they’re turning off EAS for clients <16.1. That’s another 0.4% of users—mostly Android 5.x dinosaurs—getting locked out. We’re not moving forward. We’re doing a three-step eviction. The real irony? The policy was announced in December. Previewed in September. And yet, somehow, 1.3% of users are still unprepared. That’s not negligence. That’s corporate archaeology. Microsoft didn’t break your workflow. You did. By clinging to apps older than your last corporate retreat. Now you get to watch your help desk drown—in a sea of your own legacy. Stay compliant. Or stay offline. * * * ## 💀 Why Your PDF Reader Is the New Cybersecurity Nightmare > Your PDF reader just became a backdoor. PDFSIDER APT used DLL side-loading + AES-256 DNS exfiltration to bypass AV in Fortune 100 firms. No binaries. No alerts. Just a 'Technical-Support QuickAssist' PDF. #CyberSecurity #APT #PDF24 #DNSExfiltration #DLLSideLoading Let’s be clear: the PDFSIDER APT didn’t hack your firewall. It hacked your _workflow_. Attackers delivered a phishing PDF labeled ‘Technical-Support QuickAssist’—a name so bland it could’ve been drafted by HR. When opened, it triggered PDF24 Creator v3.x to auto-update… and silently loaded a malicious `cryptbase.dll` from its own install directory. Yes. Your document converter is now a backdoor. The malware doesn’t write to disk. It lives in memory. Signature-based AV? Useless. It exfiltrates Chrome login data and cryptocurrency wallets via AES-256-GCM-encrypted DNS queries to `*.c2pdfsider.net`. Each query has entropy >4.2 bits—far beyond legitimate DNS noise. Over 250K such queries were logged before Resecurity HUNTER sinkholed the domain. This isn’t novel. It’s _standardized_. The same DLL side-loading technique was seen in LOTUSLITE and Mustang Panda campaigns. PDF24 is installed in ~12% of Fortune 100 firms. Attackers aren’t targeting you—they’re targeting the _default software stack_. Mitigation? Stop treating PDFs like harmless documents. Enforce application whitelisting. Block unsigned DLLs from non-ProgramFiles paths. Deploy DNS anomaly detection: flag labels with entropy >4 bits. Monitor for `PDFSIDER-svc` scheduled tasks. And for heaven’s sake, stop letting employees auto-update PDF tools without IT approval. Prediction: By Q2 2026, Adobe Acrobat and Foxit Reader will be next. Because if you can exploit a PDF reader, why bother with zero-days? IOCs: `3F9A…E2C4` (DLL SHA-256), `c2pdfsider.net`, `PDFSIDER-svc`. — _If your IT team still thinks ‘antivirus is enough,’ they’re not ignoring threats—they’re just out of coffee._ * * * ### In Other News * BlackBasta Ransomware Group Leaks 200,000 Internal Messages Exposing Cybercriminal Infrastructure and Wallet Addresses * SISA and Unnati Launch 'Cybersmart Bharat' Initiative to Train 25,000 Indian Students in Cybersecurity Skills * StealC Malware Infrastructure Exposed via XSS Flaw, Allowing Researchers to Monitor Cybercriminals' Own Operations * Trend Micro Deploys Trend Vision One on AWS European Sovereign Cloud to Meet NIS2 and DORA Compliance * Ohio Introduces HB524 to Impose $50,000 Penalties on AI Developers for Harmful Content Leading to Suicide * Microsoft Ends WhatsApp AI Provider Integration, Cutting ChatGPT and Copilot Access for Enterprise Users
espresso.cafecito.tech
January 20, 2026 at 1:36 PM
PDFSider Malware Used in Fortune 100 Finance Ransomware Attack #CyberAttacks #CyberSecurityRansomwareAttacks #FinanceSector
PDFSider Malware Used in Fortune 100 Finance Ransomware Attack
 A Fortune 100 finance company was targeted by ransomware actors using a new Windows malware strain called PDFSider, built to quietly deliver malicious code during intrusions. Rather than relying on brute force, the attackers used social engineering, posing as IT support staff and convincing employees to launch Microsoft Quick Assist, enabling remote access. Resecurity researchers identified the malware during incident response, describing it as a stealth backdoor engineered to avoid detection while maintaining long-term control, with traits typically associated with advanced, high-skill intrusion activity.  Resecurity previously told BleepingComputer that PDFSider had appeared in attacks connected to Qilin ransomware, but researchers emphasize it is not limited to a single group. Their threat hunting indicates the backdoor is now actively used by multiple ransomware operators as a delivery mechanism for follow-on payloads, suggesting it is spreading across criminal ecosystems rather than remaining a niche tool.  The infection chain begins with spearphishing emails containing a ZIP archive. Inside is a legitimate, digitally signed executable for PDF24 Creator, developed by Miron Geek Software GmbH, paired with a malicious DLL named cryptbase.dll. Since the application expects that DLL, it loads the attacker’s version instead. This technique, known as DLL side-loading, allows the malicious code to execute under the cover of a trusted program, helping it evade security controls that focus on the signed executable rather than the substituted library.  In some cases, attackers increase the likelihood of execution using decoy documents crafted to appear relevant to targets. One example involved a file claiming authorship from a Chinese government entity. Once launched, the malicious DLL inherits the same privileges as the legitimate executable that loaded it, increasing the attacker’s ability to operate within the system.  Resecurity notes that while the EXE remains validly signed, attackers exploited weaknesses in the PDF24 software to load the malware and bypass EDR tools more effectively. The firm also warns that AI-assisted coding is making it easier for cybercriminals to identify and exploit vulnerable software at scale. After execution, PDFSider runs primarily in memory to reduce disk traces, using anonymous pipes to issue commands through CMD.  Each infected device is assigned a unique identifier, system details are collected, and the data is exfiltrated to an attacker-controlled VPS through DNS traffic on port 53. For command-and-control security, PDFSider uses Botan 3.0.0 and encrypts communications with AES-256-GCM, decrypting inbound data only in memory to limit its footprint. It also applies AEAD authentication in GCM mode, a cryptographic approach commonly seen in stealthy remote shell backdoors designed for targeted operations.  The malware includes anti-analysis checks such as RAM size validation and debugger detection, terminating early when it suspects sandboxing. Based on its behavior and design, Resecurity assesses PDFSider as closer to espionage-grade tradecraft than typical financially motivated ransomware tooling, built to quietly preserve covert access, execute remote commands flexibly, and keep communications protected.
dlvr.it
February 4, 2026 at 3:03 PM
New PDFSider Windows malware deployed on Fortune 100 firm's network
New PDFSider Windows malware deployed on Fortune 100 firm's network
www.bleepingcomputer.com
January 20, 2026 at 9:48 AM
PDFSIDER Discovered: New APT Malware Uses DLL Side-Loading to Evade Detection
PDFSIDER Discovered: New APT Malware Uses DLL Side-Loading to Evade Detection
securityonline.info
January 20, 2026 at 7:48 AM
PDFSIDER Malware – Exploitation of DLL Side-Loading for AV and EDR Evasion
PDFSIDER Malware - Exploitation of DLL Side-Loading for AV and EDR Evasion
Threat actors use PDFSIDER with social engineering and DLL sideloading to bypass AV/EDR, and ransomware gangs already abuse it.
securityaffairs.com
January 20, 2026 at 10:28 PM
New PDFSider Windows malware deployed on Fortune 100 firm's network
New PDFSider Windows malware deployed on Fortune 100 firm's network
Ransomware attackers targeting a Fortune 100 company in the finance sector used a new malware strain, dubbed PDFSider, to deliver malicious payloads on Windows systems.
www.bleepingcomputer.com
January 19, 2026 at 9:08 PM
PDFSIDER Malware Actively Used by Threat Actors to Bypass Antivirus and EDR Systems
PDFSIDER Malware Actively Used by Threat Actors to Bypass Antivirus and EDR Systems
PDFSIDER is a newly exposed backdoor that gives attackers long term control of Windows systems while slipping past many antivirus and endpoint detection and response tools. It uses trusted software and strong encryption to hide its presence, letting intruders run commands, study the network, and move deeper inside targeted environments. The campaign behind PDFSIDER relies on focused spear phishing. Victims receive emails that deliver a ZIP archive holding a legitimate PDF24 Creator executable, signed with a valid certificate, along with other companion files. PDFSIDER analysis diagram (Source – Resecurity) When the user launches the trusted app, a hidden payload is triggered instead of any obvious document viewer, starting the breach with almost no visible signs. Resecurity analysts identified PDFSIDER during an attempted intrusion against a Fortune 100 enterprise that was stopped before data loss occurred. Malware and legitmate app (Source – Resecurity) Their investigation showed that the malware is already being used by multiple ransomware groups and advanced actors as a reliable payload loader that can slip around standard security controls. The tool’s design more closely matches espionage tradecraft than smash and grab crime. Impact on defenders The impact on defenders is serious because PDFSIDER blends a valid application, a fake Windows cryptbase.dll, and encrypted command and control traffic over DNS port 53. DLL sideloading attack (Source – Resecurity) By operating mainly in memory, checking for virtual machines and debuggers, and avoiding noisy exploit chains, it makes traditional signature based detection and sandbox testing far less effective. The infection flow begins when the victim runs the trojanized PDF24 executable from the delivered archive. In the same folder, the attackers place a malicious cryptbase.dll that abuses DLL side loading rules, so the program loads their library instead of the real system file. Once loaded, PDFSIDER initializes Winsock, gathers system details, builds a unique host identifier, and sets up an in memory backdoor loop. Next, the malware creates anonymous pipes and launches a hidden cmd.exe process using the CREATE_NO_WINDOW flag. Any commands sent by the operators are executed without a console window, and the output is captured and sent back over an AES 256 GCM encrypted channel powered by the Botan library. Because all traffic is strongly protected and never written to disk, security tools see only normal looking DNS requests while attackers enjoy full remote shell control. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post PDFSIDER Malware Actively Used by Threat Actors to Bypass Antivirus and EDR Systems appeared first on Cyber Security News .
cybersecuritynews.com
January 19, 2026 at 10:22 AM
New 'PDFSIDER' backdoor uses DLL side-loading with a legit PDF app to bypass EDR/AV. It creates an encrypted C2 channel for stealthy access and is already used by the Qilin ransomware group. 🛡️ #Malware #Backdoor #EDR #Qilin #ThreatIntel
Stealthy
Researchers have uncovered
cyber.netsecops.io
January 20, 2026 at 5:05 PM
PDFSIDER Malware - Exploitation of DLL Side-Loading for AV and EDR Evasion
PDFSIDER Malware - Exploitation of DLL Side-Loading for AV and EDR Evasion
www.resecurity.com
January 25, 2026 at 2:54 PM
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 81

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter UNO reverse card: stealing cookies from cookie stealers  PDFSIDER Malware – Exploi…
#hackernews #news
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 81
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter UNO reverse card: stealing cookies from cookie stealers  PDFSIDER Malware – Exploitation of DLL Side-Loading for AV and EDR Evasion   VoidLink: Evidence That the Era of Advanced AI-Generated Malware Has Begun  PyPI Package Impersonates […]
securityaffairs.com
January 26, 2026 at 11:32 AM