Check Point Research reported active in-the-wild exploitation of a Foxit PDF Reader design flaw that lets malicious PDF files abuse the /OpenAction and /Launch features to display misleading default prompts and trick users into running external commands. The behavior differs from Adobe Reader, and researchers said that gap helped attackers evade sandboxes and antivirus products that primarily emulate Adobe software. Foxit acknowledged the issue and said a fix was planned for version 2024.3.
Researchers linked the activity to multiple threat actors across both cybercrime and espionage operations, with observed payloads including VenomRAT, Agent Tesla, Remcos, NjRAT, NanoCore RAT, Pony, Xworm, AsyncRAT, DCRat, Blank-Grabber, and cryptocurrency miners. Check Point highlighted several campaigns, including a military-themed espionage chain attributed to APT-C-35/DoNot Team, a Facebook-distributed stealer-and-cryptominer operation, a Python-based Blank-Grabber delivery chain, and a multi-stage Remcos infection using Trello-hosted PDFs and DynamicWrapperX-based shellcode injection; the researchers also identified Python and .NET builders used to generate the weaponized PDFs.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
Check Point Research documented active exploitation of a Foxit PDF Reader design flaw in which malicious PDFs abuse /OpenAction and /Launch behavior to trick users into executing external commands. The report says multiple threat actors used the technique and that Adobe Reader does not exhibit the same exploit path.
The report states that Foxit acknowledged the abused design issue and planned a fix in version 2024.3. This reflects the vendor response to the exploitation technique documented by Check Point.
Researchers analyzed a fourth campaign in which an initial PDF linked via Trello to a second malicious PDF, "Facebook_Adversting_project.pdf," that downloaded a .lnk file and progressed through HTA and VBScript stages to Remcos RAT. The chain used DynamicWrapperX for shellcode injection and the final sample communicated with 139.99.85[.]106:2404 under the botnet name "Telegram : @Silentkillertv."
Check Point identified a third campaign in which a malicious Foxit-targeting PDF downloaded lol.pyw from Discord CDN to deploy the open-source Blank-Grabber Python stealer. The stealer included anti-VM checks, analysis-tool termination, browser and application theft, and UAC bypass routines.
A second campaign used a PDF named "swift v2.pdf," distributed via Facebook, to launch cmd.exe, fetch a BAT file, install Python, and run a Python-based stealer targeting browser credentials and cookies. The same chain also downloaded and executed XMRig and lolMiner from attacker-controlled resources.
Researchers analyzed a military-themed PDF lure tied to a Foxit exploitation chain and assessed the espionage-focused campaign as likely conducted by APT-C-35, also known as DoNot Team. The malware collected host details, established persistence, downloaded additional payloads, staged files for theft, and uploaded them to attacker infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 64 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.