PDFSupernova is a fake PDF-converter application described in the content as browser-hijacking malware, with possible credential-stealing or credential-harvesting functionality, targeting Google Chrome on Windows. Rather than providing a legitimate converter, the analyzed installer delivered only a shortcut to a PDF conversion website, displayed language seeking agreement to change default search settings, took focus from the user, and killed chrome.exe during execution. The malware handled Chrome's "Web Data" SQLite profile database, created or retrieved a replacement "Web Data" file in AppData\Local\Temp, and overwrote the victim's Chrome profile Web Data file with it. The modified database contained vanmirop-related keyword filters and autofill or credential-related entries, including references to multiple financial institutions. After infection, address-bar searches were hijacked through infrastructure including novaserv.vanmirop.com, api.vanderconf.com, withgoogle.com, van.vanmirop.com, eusrchrdr.com, undertone.com, cdn.searchontec.com, sync.cootlogix.com, and os.gotosearch.co, ultimately redirecting queries to Yahoo. The sample dropped DLLs including av_libglesv2.dll, libHarfBuzzSharp.dll, and libSkiaSharp.dll under a pdfsupernova subdirectory; these appeared to be legitimate AvaloniaUI-related dependencies. The content also notes server-side delivery of .NET code in connection with PDFSupernova. A PDB path referenced Supernova.pdb under a net8.0 win-x64 build path. The malware was observed signed with a code-signing certificate for Trivolead LTD, and a newer March 2026 version was observed signed by Magnivicent LTD while still communicating with the same domain and using the same key. The content links PDFSupernova to a broader cluster of malicious PDF-themed applications and similar variants including PrimePDFConvert, PDFChampions, PDFParade, and pdfrogger.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a similar malware/setup for comparison to PowerDoc.
Referenced as a similar browser hijacking malware family for comparison with PrimePDFConvert.
A fake PDF/converter application that overwrites Chrome's Web Data profile database, kills chrome.exe, hijacks browser search settings to attacker-controlled domains, injects autofill/login-related data, and appears capable of credential theft. Later analysis notes extracted .NET components and related loader-like behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.