Threat Intelligence, Malware

Malware disguised as PDF tool turns PCs into proxies

Privacy concept: pixelated words Malware on digital background, 3d render

Cybersecurity analysts have warned of a new malware campaign that disguises itself as a legitimate PDF editor but secretly converts infected devices into residential proxies, Cyber Security News reports.

According to ExpelSecurity, the attack leverages files signed with the certificate "GLINT SOFTWARE SDN. BHD." to appear credible, while deploying a trojan known as "ManualFinder." The infection process begins with JavaScript components launched through the problematic OneStart Browser, which creates scheduled tasks to ensure persistence. Researchers noted the malware communicates with command-and-control domains such as mka3e8[.]com to deliver additional payloads under the same fraudulent certificate. What makes this threat particularly deceptive is its dual nature: in sandbox testing, ManualFinder performs its advertised role of locating product manuals, masking its malicious intent. Behind the faade, however, the malware reroutes traffic through victim devices, enabling attackers to profit from proxy operations while concealing the true origin of illicit activity. Analysts stress the campaign reflects an advanced effort to evade traditional detection systems.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds