Security researchers reported multiple malware campaigns using trojanized utility software—including fake PDF converters, ZIP tools, and a malicious PDF editor—to infect users who arrive via search ads and download portals. Intezer identified two families, SilentMare and HollowMare, embedded in seemingly legitimate utilities: SilentMare acts as a downloader and foothold, using custom installers, scheduled-task persistence, daily updater check-ins, and AES-encrypted .NET payloads executed in memory, while HollowMare behaves more like a potentially unwanted application that installs browser extensions or hijacks default search settings. Truesec separately described a malicious Appsuite PDF Editor delivering TamperedChef, reinforcing the use of fake productivity tools as an infection vector.
The reporting shows a broader resurgence of Trojan horse delivery through software impersonation, including lures tied to AI-themed branding and homoglyph abuse to make malicious sites and applications appear legitimate. Intezer said SilentMare and HollowMare shared some infrastructure and code-signing certificate procurement patterns, including certificates issued to Israeli entities, but found the evidence insufficient to attribute both families to the same actor. Researchers advised blocking these utilities in enterprise environments because even apparently functional apps may upload user files to untrusted servers, establish persistence, or alter browser behavior without a second-stage payload.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
In January 2026, researchers discovered the SagePDF HollowMare variant. It returned to keystroke-based browser hijacking and dropped the persistence mechanism.
The OneZip HollowMare variant was first publicly seen on VirusTotal in November 2025. Unlike earlier variants, it modified browser profile files to hijack settings and targeted Firefox.
In fall 2025, SilentMare appeared in applications including Rapid Doc and ZapPDF. Rapid Doc used a modified PyInstaller-based installer, while ZapPDF used a custom C# installer that downloaded the updater, and the updater itself was reimplemented in C++.
In August 2025, a new SilentMare generation used trojanized applications including Easy 2 Convert and Convert Mate. This version installed its updater only if Google Chrome was present and used an F# updater with timestamp-derived AES keying.
The earliest HollowMare variant was spread in May 2025 through ConvertyFile. It used a Go-based installer, contacted C2 to choose the browser extension target, and automated installation with a full-screen window and synthetic keyboard input.
Intezer tracked the SilentMare malware family back to 2024, when early applications such as PDF Skills and Zip This were distributed as trojanized utilities. This generation used custom .NET installers and updater components with mixed managed C# and unmanaged C++ code.
Intezer published research documenting the SilentMare and HollowMare trojanized utility families, their distribution through fake utility apps, and shared infrastructure and certificate-procurement patterns. The report concluded both families should be blocked in enterprise environments, while noting the evidence was insufficient to attribute them to the same actor.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 119 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
research.intezer.com
Open sourcetruesec.com
Open sourcegdatasoftware.com
Open sourceguidepointsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.