PULSE NAME
Foxit Impersonation: Fake PDF Installer Deploys VNC
WHITE AlienVault 2026-04-23 Modified: 2026-04-23
11
IOCs
MEDIUM VOLUME
Attackers are leveraging the trusted reputation of Foxit PDF Reader, used by over 650 million people, to distribute malicious installers disguised as legitimate software. Rather than exploiting vulnerabilities, threat actors impersonate the vendor through fake installers with document-themed filenames that bypass user suspicion. When executed, these files display decoy passport images while downloading malicious MSI packages that deploy UltraVNC remote access tools disguised as GPU drivers. The attack establishes persistence through registry modifications and firewall exceptions, connecting to attacker-controlled infrastructure for complete remote system control. Telemetry indicates broad distribution across Germany, the United States, the United Kingdom, and Ukraine. This campaign demonstrates how brand impersonation combined with social engineering proves more effective than technical exploits, relying on user trust and behavioral patterns rather than software vulnerabilities.
Indicators of Compromise (11)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 8e4aca0e510ea932b616f77d767ca5a9 2026-04-23
FileHash-MD5 d6829f4abe09dba254d560f91f56f83b 2026-04-23
FileHash-SHA1 72230761f27a0d8482c795b1101887cac7acb9d8 2026-04-23
FileHash-SHA1 e067eac14eafde7ccd99f83ec21fa09a6cfe601a 2026-04-23
FileHash-SHA256 08b9cbdae903faf88b8027a12eee29265ff9b192b63aaa371d3d095b8ec00de5 2026-04-23
FileHash-SHA256 37c5723aeb725b1aec98da1f776fd841176c687d8ad5c2a14a6ebd831f1615d1 2026-04-23
FileHash-SHA256 87e168467d409be8c3aa8e67d3bc90a10b9769e2f63a0e1bad6b906bfd87ef61 2026-04-23
FileHash-SHA256 b7dbab109e5bf3afffba5571366602154f3ea37053ec210dd3e030d0fcb2dbaa 2026-04-23
FileHash-SHA256 bba4e6028ffa239375d7778b2b5b138b52af0d6a2cfdc99dbadab53373a570f5 2026-04-23
URL http://hallonews.servemp3.com:5500 2026-04-23
URL https://juneuk25.cfd/personalfoxypdf.msi 2026-04-23