Knowledge Centre
Home / News / Cyber Insurance News / Multiple Threat Actors Exploit Foxit PDF Reader Flaw to Spread Malware

Multiple Threat Actors Exploit Foxit PDF Reader Flaw to Spread Malware

Published on May 23, 2024. EST READ TIME: 2 minutes

Multiple Threat Actors Exploit Foxit PDF Reader Flaw to Spread Malware

Multiple threat actors are exploiting a design flaw in Foxit PDF Reader to spread various malware, such as Agent Tesla, AsyncRAT, and Remcos RAT. According to Check Point, the flaw misleads users into executing harmful commands by displaying deceptive pop-ups with default "OK" and "Open" options. Malicious payloads are often hosted on Discord's content delivery network (CDN), contributing to the campaign's low detection rate. Notably, Adobe Acrobat Reader, more common in sandboxes or antivirus solutions, is not susceptible to this exploit. This flaw is exploited by a range of actors from e-crime to espionage, including the DoNot Team. Malicious PDFs have been distributed through platforms like Facebook and Trello. Check Point identified several instances where the attack chain involved downloading additional malware, such as credential stealers and cryptocurrency miners, from repositories like Gitlab.

Awards & Recognition
Image

BFSI Leadership Awards 2022 - Product Innovator of the Year (Optima Secure)

ETBFSI Excellence Awards 2021

FICCI Insurance Industry
Awards September 2021

ICAI Awards 2015-16

SKOCH Order-of-Merit

Best Customer Experience
Award of the Year

ICAI Awards 2014-15

Image

CMS Outstanding Affiliate World-Class Service Award 2015

Image

iAAA rating

Image

ISO Certification

Image

Best Insurance Company in Private Sector - General 2014

View all awards