216.73.216.6

Backdoor in "AppSuite PDF Editor": A Detailed Technical Analysis

· Published 28/08/2025 18:26 · Modified 28/08/2025 19:15

Export JSON

Essential information

Published
28/08/2025 18:26
Modified
28/08/2025 19:15
Tags
2025-08-28 aes encryption appsuite appsuite pdf editor backdoor browser manipulation command and control data exfiltration pdf editor scheduled tasks trojan
Related entities
9 observables, 16 techniques (mitre), 1 malware

Description

A detailed analysis of a malicious application called reveals it to be a sophisticated . The software, masquerading as a legitimate productivity tool, is distributed through high-ranking websites. Once installed, it creates and establishes persistence mechanisms. The communicates with servers, allowing threat actors to execute arbitrary commands, exfiltrate data, and manipulate browser settings. It specifically targets Chromium-based browsers and other applications like Wave browser, Shift browser, and OneLaunch. The malware employs advanced techniques such as , custom obfuscation, and event logging to evade detection. The analysis concludes that is definitively malicious and should be classified as a horse with capabilities.

External references