Researchers reported overlapping malware campaigns that use fake or trojanized PDF reader packages to compromise Windows systems through DLL sideloading. Cisco Talos identified PXA Stealer targeting government and education organizations, while Beazley Security and SentinelLabs said the Python-based infostealer has operated at scale since late 2024, affecting more than 4,000 victims in 62 countries. The activity has been linked to Vietnamese-speaking threat actors who used phishing, signed software such as Haihaisoft PDF Reader and Microsoft Word 2013, and multi-stage loaders to evade detection and establish persistence through Windows Run registry keys.
The malware chains ultimately steal browser credentials, cookies, autofill data, cryptocurrency wallet contents, and other sensitive application data, with exfiltration routed through Telegram bots and Cloudflare Workers and ties observed to the Sherlock stolen-data marketplace. In a related development, Kroll said XWORM operators adopted a similar fake PDF reader delivery chain using Ghost Crypt, packaging a renamed Haihaisoft executable, a malicious DLL, and a decoy PDF in a ZIP archive. That infection path uses a "process hypnosis" technique to inject payloads into csc.exe, persists via rundll32.exe, and ends with a plugin-based RAT capable of information theft and ransomware-related actions.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
In July 2025 samples, researchers identified a Telegram bot token and chat ID used by PXA Stealer to exfiltrate stolen data through Cloudflare Worker relays. The same samples showed browser-targeting DLL injection against Edge, Chrome, Whale, and CocCoc.
Beazley Security and SentinelLabs observed the attackers evolve their infection chain in July 2025 to use a legitimate signed Microsoft Word 2013 executable with a sideloaded malicious msvcr100.dll. The archive also included hidden support files and a decoy document to disguise the attack.
Kroll reported that starting in July 2025, XWORM began using Ghost Crypt in a ZIP-based delivery chain that abused DLL sideloading in a fake HaiHaiSoft PDF Reader package. The bundled executable loaded a malicious local DLL when the victim opened the included PDF.
In an April 2025 wave, the actors used a signed copy of Haihaisoft PDF Reader with a malicious DLL to sideload malware. The chain established persistence via a Windows Registry Run key and retrieved additional payloads from Dropbox.
Beazley Security and SentinelLabs said the PXA Stealer campaign had been active since late 2024, with some Telegram bot IDs created as early as October 2024. Early waves delivered infostealers such as LummaC2 and Rhadamanthys before the actors shifted to updated Python-based payloads.
Kroll disclosed technical details on Ghost Crypt's process-hypnosis injection into csc.exe, Run-key persistence via rundll32.exe, and the final XWORM payload's configuration decryption and TCP C2 behavior. The report also linked Ghost Crypt to a service advertised on HackForums that supports multiple malware families.
Beazley Security and SentinelLabs described an ongoing infostealer operation attributed to Vietnamese-speaking actors and tied to a Telegram-based criminal marketplace. They reported more than 4,000 unique victims across 62 countries and detailed theft of browser, financial, and cryptocurrency data.
Cisco Talos published research on a new PXA Stealer campaign targeting government and education sectors for sensitive information. The reference establishes public reporting on the malware by mid-November 2024.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
kroll.com
Open sourcelabs.beazley.security
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.