Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Google is sunsetting the weather app on Android

    Nvidia could launch its first laptops with its own processors later this year

    AMD reportedly pauses Ryzen Z1 drivers for gaming handhelds

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Tensions between the Pentagon and AI giant Anthropic reach a boiling point

      February 21, 2026

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026
    • Business

      Gartner: Why neoclouds are the future of GPU-as-a-Service

      February 21, 2026

      The HDD brand that brought you the 1.8-inch, 2.5-inch, and 3.5-inch hard drives is now back with a $19 pocket-sized personal cloud for your smartphones

      February 12, 2026

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026
    • Crypto

      XRP Struggles as On-Chain Stress Mounts: Is a Bottom Forming?

      February 23, 2026

      Vitalik Buterin Sold Over 8,800 ETH in February: Did It Impact the Price?

      February 23, 2026

      Vitalik Buterin Explains How Crypto Can Protect Users When Perfect Security Remains Impossible

      February 23, 2026

      Ethereum, Solana Defy L1 Myth — Bitwise CIO Sees Prediction Markets Changing Everything

      February 23, 2026

      5 Critical Factors That Could End Gold’s 7-Month Green Streak

      February 23, 2026
    • Technology

      Google is sunsetting the weather app on Android

      February 23, 2026

      Nvidia could launch its first laptops with its own processors later this year

      February 23, 2026

      AMD reportedly pauses Ryzen Z1 drivers for gaming handhelds

      February 23, 2026

      Here’s your chance to grab a cheaper Cybertruck but you have to hurry

      February 23, 2026

      Rocket reentries are leaving measurable lithium pollution in the upper atmosphere

      February 23, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»New PDFSider Windows malware deployed on Fortune 100 firm’s network
    Technology

    New PDFSider Windows malware deployed on Fortune 100 firm’s network

    TechAiVerseBy TechAiVerseJanuary 20, 2026No Comments3 Mins Read1 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    New PDFSider Windows malware deployed on Fortune 100 firm’s network
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    New PDFSider Windows malware deployed on Fortune 100 firm’s network

    Ransomware attackers targeting a Fortune 100 company in the finance sector used a new malware strain, dubbed PDFSider, to deliver malicious payloads on Windows systems.

    The attackers employed social engineering in their attempt to gain remote access by impersonating technical support workers and to trick company employees into installing Microsoft’s Quick Assist tool.

    Researchers at cybersecurity company Resecurity found PDFSider during an incident response and describe it as a stealthy backdoor for long-term access, noting that it shows “characteristics commonly associated with APT tradecraft.”

    Legit .EXE, malicious .DLL

    A Resecurity spokesperson told BleepingComputer that PDFSider has been seen deployed in Qilin ransomware attacks. However, the company’s threat hunting team notes that the backdoor is already “actively used” by multiple ransomware actors to launch their payloads.

    The PDFSider backdoor is delivered via spearphishing emails that carry a ZIP archive with a legitimate, digitally signed executable for the PDF24 Creator tool from Miron Geek Software GmbH. However, the package also includes a malicious version of a DLL (cryptbase.dll), which the application requires to function properly.

    When the executable runs, it loads the attacker’s DLL file, a technique known as DLL side-loading, and provides code execution on the system.

    The executable’s valid signature
    Source: Resecurity

    In other cases, the attacker attempts to trick email recipients into launching the malicious file by using decoy documents that appear to be tailored to the targets. In one example, they used a Chinese government entity as the author.

    Once launched, the DLL runs with the rights of the executable that loaded it.

    “The EXE file has a legitimate signature; however, the PDF24 software has vulnerabilities that attackers were able to exploit to load this malware and bypass EDR systems effectively,” Resecurity explains.

    According to the researchers, finding vulnerable software that can be exploited is becoming easier for cybercriminals, due to the rise of AI-powered coding.

    PDFSider loads straight into memory, leaving minimal disk artifacts, and uses anonymous pipes to launch commands via CMD.

    Infected hosts are assigned a unique identifier, and system information is collected and exfiltrated to the attacker’s VPS server over DNS (port 53).

    PDFSider protects its command-and-control (C2) exchange by using the Botan 3.0.0 cryptographic library and AES-256-GCM for encryption, decrypting incoming data in memory to minimize its footprint on the host.

    Moreover, the data is authenticated using Authenticated Encryption with Associated Data (AEAD) in GCM mode.

    “This type of cryptographic implementation is typical of remote shell malware used in targeted attacks, where maintaining the integrity and confidentiality of communications is critical,” Resecurity notes.

    PDFSider operational overview
    Source: Resecurity

    The malware also features several anti-analysis mechanisms, such as RAM size checks and debugger detection, to exit early when signs of running in a sandbox are detected.

    Based on its assessment, Resecurity says that PDFSider is closer to “espionage tradecraft than financially motivated malware” and is built as a stealthy backdoor that can maintain long-term covert access and provide flexible remote command execution and encrypted communication.


    7 Security Best Practices for MCP

    As MCP (Model Context Protocol) becomes the standard for connecting LLMs to tools and data, security teams are moving fast to keep these new services safe.

    This free cheat sheet outlines 7 best practices you can start using today.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleUK govt. warns about ongoing Russian hacktivist group attacks
    Next Article Fake ad blocker extension crashes the browser for ClickFix attacks
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Google is sunsetting the weather app on Android

    February 23, 2026

    Nvidia could launch its first laptops with its own processors later this year

    February 23, 2026

    AMD reportedly pauses Ryzen Z1 drivers for gaming handhelds

    February 23, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025690 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025278 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025159 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025120 Views
    Don't Miss
    Technology February 23, 2026

    Google is sunsetting the weather app on Android

    Google is sunsetting the weather app on Android Google is replacing the long-standing shortcut with…

    Nvidia could launch its first laptops with its own processors later this year

    AMD reportedly pauses Ryzen Z1 drivers for gaming handhelds

    Here’s your chance to grab a cheaper Cybertruck but you have to hurry

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Google is sunsetting the weather app on Android

    February 23, 20262 Views

    Nvidia could launch its first laptops with its own processors later this year

    February 23, 20261 Views

    AMD reportedly pauses Ryzen Z1 drivers for gaming handhelds

    February 23, 20262 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.