#SumatraPDF
Malware/Tool
2024-01-19 • APT-C-26(Lazarus)组织使用武器化的开源PDF阅读器的攻击活动分析
SumatraPDF in this context is a weaponized Windows build of the open-source SumatraPDF Reader 2.5.1 used in Lazarus-attributed activity. Opening a crafted document with the altered application activates encrypted content hidden in the PDF, decrypts and executes a loader in memory, and progresses through additional encrypted stages. A downloader then contacts attacker-controlled infrastructure to retrieve a backdoor intended for sensitive-information theft. The activity primarily targeted financial institutions and cryptocurrency exchanges through malicious documents paired with the trojanized reader.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days