Researchers reported that Projextor is masquerading as legitimate desktop tools, including document converters, meal planners, and recipe applications, to infect users through lookalike download sites and common installer frameworks. The campaign delivers a second-stage Electron application that continues to function as expected while concealing malicious behavior, allowing the malware to blend into normal user activity and evade suspicion.
According to reporting tied to the campaign, the malware abuses Electron by replacing or adding malicious main.js and preload.js files in the application resources directory, disabling context isolation, and enabling execution of additional JavaScript modules after installation. Indicator data linked to the activity includes domains such as doceditorinc[.]com, meal-formula[.]com, kitchen-canvas[.]com, flipformatpdf[.]com, and pdfgrip[.]com, as well as a staging path at conv.doceditorinc[.]com/latest/part; researchers also warned that Projextor includes screen-capture capability that could expose documents, browser sessions, email, and business application data visible on infected systems.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Published indicators tied the campaign to domains including doceditorinc[.]com, meal-formula[.]com, kitchen-canvas[.]com, flipformatpdf[.]com, and pdfgrip[.]com, as well as the path conv.doceditorinc[.]com/latest/part. The references also listed SHA-256 hashes for FlipFormat, PDFGrip, FoodFormula, KitchenCanvas, preload.js, and main.js samples.
Researchers found that Projextor included a custom screen-sharing picker that listed monitors and application windows with thumbnails. This capability could expose sensitive information visible during live user sessions, including documents, browser activity, email, and business applications.
G Data reported that Projextor installs malicious main.js and preload.js files in the Electron application resources directory, where they launch automatically at startup. In observed samples, main.js disabled Electron context isolation and allowed additional JavaScript modules to be loaded from an injection directory after installation.
Researchers at G Data identified Projextor as a malware campaign that hides malicious code inside legitimate-looking desktop utilities such as document converters, meal planners, and recipe applications. They found the campaign used lookalike download sites and common installer frameworks to deliver a second-stage Electron application that remained functional while concealing malicious behavior.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.