Resecurity reported on PDFSIDER, a newly identified Windows backdoor distributed via spear-phishing that delivers a ZIP containing a legitimate, validly signed PDF24 Creator executable alongside a malicious cryptbase.dll. When the victim runs the trusted PDF24 binary, DLL side-loading causes the fake cryptbase.dll to load, triggering covert backdoor execution with minimal user-visible artifacts and strong evasion features (e.g., anti-VM/anti-debug checks and in-memory behavior).
The malware implements encrypted command-and-control using an embedded Botan cryptographic library and AES-256-GCM, enabling interactive remote command execution and system reconnaissance while reducing detection opportunities. Reporting indicates PDFSIDER’s C2 can be tunneled over DNS (port 53) and that the tooling is already being leveraged by multiple threat actors, including ransomware operators, as a stealthy payload loader; Resecurity stated it was identified during an attempted intrusion against a Fortune 100 organization that was disrupted before data loss occurred.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Resecurity assessed that PDFSIDER was already being used by multiple ransomware actors, including observed use in Qilin attacks, while also noting the tooling looked more espionage-oriented than typical crimeware. The report further cited moderate-confidence overlap with Mustang Panda-style tradecraft and decoy documents impersonating PLA intelligence authorship.
Researchers disclosed that PDFSIDER communicated with attacker infrastructure over DNS on port 53 and protected command-and-control traffic with Botan and AES-256-GCM authenticated encryption. The malware also assigned unique host IDs, exfiltrated command output, and maintained covert long-term access with minimal disk artifacts.
Resecurity reported that the PDFSIDER-related intrusion against the Fortune 100 enterprise was stopped before data loss occurred. The finding came from the company's incident response and prevented-intrusion investigation.
Resecurity identified a new malware variant dubbed PDFSIDER that abused DLL side-loading by pairing a legitimate signed PDF24 executable with a malicious fake cryptbase.dll. The malware operated largely in memory, performed host reconnaissance, enabled hidden remote shell access, and used anti-VM and debugger checks to evade analysis.
During an intrusion attempt against a Fortune 100 company in the finance or energy sector, attackers impersonated technical support to persuade employees to install Microsoft Quick Assist for remote access. The same activity also used spear-phishing emails with ZIP archives to deliver the malware chain.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityonline.info
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourceresecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.