Saturday, May 17, 2025
HomeComputer SecurityEvil Clone Attack - Hackers Injecting Crypto-mining Malware into Legitimate PDF Software

Evil Clone Attack – Hackers Injecting Crypto-mining Malware into Legitimate PDF Software

Published on

SIEM as a Service

Follow Us on Google News

Cybercriminals using a new type of attack called Evil clone to inject Cryptocurrency malware into legitimate PDF software to Mine cryptocurrency with the help of CoinHive miner.

Cryptocurrency malware is dramatically increasing this year to compromise various victims and an attacker generates huge revenue by illegally running miner using victims system resource.

Attackers abusing legitimate PDFescape software application installer to modify the package in order to delivery the crypto-mining malware.

- Advertisement - Google News

PDFescape is a web-based PDF editor program written in JavaScript, HTML, CSS and ASP. Many Peoples using this software for PDF editing, form filling, page arrangement, printing, saving, and form publishing.

Cybercriminals always using legitimate software to perform malicious activities by applying various modification even though legitimate software’s are secure to use.

In this case, the Attacker went to a depth into the legitimate PDF software PDFescape and create a evil clone.

Cryptomining Malware Injecting Process

Initially, attacker created the similar infrastructure on a server which is controlled by an attacker same as legitimate software vendor infrastructure.

Later they copied all the MSI file from the PDFescape software (installer package file for Windows) and placed it into the newly created infrastructure.

An attacker then decompiled and modified one of MSI and also added the additional malicious files which is represented the coin miner source code that turns the original installer of PDFescape into a malicious one.

This new installer redirect victims into malicious website and downloads the payload with the hidden file.

Attackers spreading this malicious package(pdfescape-desktop-Asian-and-extended-font-pack) in various form, once victim download and execute this malicious file then it drops malicious binary xbox-service.exe.

Then it runs malicious DLL under rundll32 with the name setup.log using the command line:

rundll32 C:\Windows\System32\setup.log.dll

Researchers from Comodo Cybersecurity performed a static analysis that reveals after the DLL file runs malicious process xbox-service.exe,  DLL payload tries to modify the Windows HOSTS file to prevent the infected machine from communication with update servers of various PDF-related apps and security software. Thus malware tries to avoid a remote cleaning and remediation of affected machines.

finally, the malicious DLL contains a dangerous browser script with an embedded link http://carma666.byethost12.com/32.html.

Once the embedded link will be executed then it downloads JavaScript of coinminer named CoinHive that utilize the infected system resource and generate the revenue.

Also Read:

Malware Abuse Google Ads to Injecting Coinhive Cryptocurrency Miner

Chinese Threat Actors Rocke Launching Sophisticated Crypto-mining Malware to Mine Monero Cryptocurrency

Latest articles

VMware ESXi, Firefox, Red Hat Linux & SharePoint Hacked – Pwn2Own Day 2

Security researchers demonstrated their prowess on the second day of Pwn2Own Berlin 2025, discovering...

Critical WordPress Plugin Flaw Puts Over 10,000 Sites of Cyberattack

A serious security flaw affecting the Eventin plugin, a popular event management solution for...

Sophisticated NPM Attack Leverages Google Calendar2 for Advanced Communication

A startling discovery in the npm ecosystem has revealed a highly sophisticated malware campaign...

New Ransomware Attack Targets Elon Musk Supporters Using PowerShell to Deploy Payloads

A newly identified ransomware campaign has emerged, seemingly targeting supporters of Elon Musk through...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Printer Company Distributes Malicious Drivers Infected with XRed Malware

Procolored, a printer manufacturing company, has been found distributing software drivers infected with malicious...

Frigidstealer Malware Targets macOS Users to Harvest Login Credentials

An macOS users, a new information-stealing malware dubbed FrigidStealer has emerged as a formidable...

SSH Auth Key Reuse Uncovers Advanced Targeted Phishing Campaign

A meticulously orchestrated phishing campaign targeting Kuwait's fisheries, telecommunications, and insurance sectors has been...