PDFChampions is a YAPA browser hijacker with loader capabilities that masquerades as a PDF conversion utility and is delivered via online advertisements. In the observed campaign, an ad served on govsalaries[.]com and associated with OSADS LTD redirected users to pdfchampions[.]com, which delivered PDFChampions.exe from downloadive[.]com. The installer required EULA acceptance, displayed full-screen installation views that obscured browser activity, and created a desktop shortcut to the online converter at champion.pdfchampions[.]com as well as a Start Menu uninstall shortcut to pdfchampions[.]com/uninstall.
Functionally, PDFChampions targets Firefox and changes the default search engine to Mariosearch. It retrieves configuration data from api.mekanfig[.]com/api/v1/message, including a cfg segment stating that installation changes the default search engine and providing a ConfigUri on more.mariosearch[.]com. The malware requests a Firefox search configuration from more.mariosearch[.]com using a profile-specific profile_id, receives a search.json.mozlz4 file, terminates firefox.exe processes, and copies the downloaded search.json.mozlz4 into Firefox profile directories to hijack search settings. Observed Mariosearch traffic redirected user queries to Google Search while preserving tracking parameters such as uid, pid, install_date, and q={searchTerms}.
Unlike related hijackers ConvertMaster and ConvertyFile, PDFChampions also acts as a loader. After retrieving the cfg segment, it fetched additional segments from api.mekanfig[.]com, including dets and seof. The dets segment contained C# code that enumerated operating system details and Firefox version information. The malware used a function named RunDynamicMethod to download C# code, compile it into an in-memory assembly, cache it, and execute it without writing the compiled assembly to disk. The short segment contained code to create icon files and internet shortcuts, and the seof segment contained the Firefox search hijack logic.
High-confidence indicators and artifacts mentioned in the content include PDFChampions.exe with SHA-256 7c5004c9d3ed4325c547ec0127d59205529f4574444a9e74dc108b0783d6e392; delivery URL hxxps://downloadive[.]com/puoyder/o/PDFChampions.exe; landing page hxxps://pdfchampions[.]com/pdfchampions; configuration endpoint hxxps://api.mekanfig[.]com/api/v1/message; Mariosearch infrastructure on more.mariosearch[.]com; and the Firefox search configuration file search.json.mozlz4. The research explicitly links PDFChampions to prior browser hijackers ConvertMaster and ConvertyFile based on campaign similarities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Browser hijacker delivered via ads that changes the default Firefox search engine to Mariosearch and also acts as a loader by fetching dynamic code from a remote server, compiling it in memory, and executing it. It creates desktop/start menu shortcuts to its web properties and modifies Firefox profile configuration via search.json.mozlz4 files.
Referenced by title only as a browser hijacker/loader analysis item; no further details are provided in the content.
A related fake PDF application sample discussed as similar to PDFSupernova; the content implies comparable malicious behavior but does not provide detailed functionality here.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.