Backdoor in "AppSuite PDF Editor": A Detailed Technical Analysis

Aug. 28, 2025, 7:15 p.m.

Description

A detailed analysis of a malicious PDF editor application called AppSuite PDF Editor reveals it to be a sophisticated backdoor. The software, masquerading as a legitimate productivity tool, is distributed through high-ranking websites. Once installed, it creates scheduled tasks and establishes persistence mechanisms. The backdoor communicates with command and control servers, allowing threat actors to execute arbitrary commands, exfiltrate data, and manipulate browser settings. It specifically targets Chromium-based browsers and other applications like Wave browser, Shift browser, and OneLaunch. The malware employs advanced techniques such as AES encryption, custom obfuscation, and event logging to evade detection. The analysis concludes that AppSuite PDF Editor is definitively malicious and should be classified as a trojan horse with backdoor capabilities.

Date

  • Created: Aug. 28, 2025, 6:26 p.m.
  • Published: Aug. 28, 2025, 6:26 p.m.
  • Modified: Aug. 28, 2025, 7:15 p.m.

Indicators

  • fde67ba523b2c1e517d679ad4eaf87925c6bbf2f171b9212462dc9a855faa34b
  • cb15e1ec1a472631c53378d54f2043ba57586e3a28329c9dbf40cb69d7c10d2c
  • b3ef2e11c855f4812e64230632f125db5e7da1df3e9e34fdb2f088ebe5e16603
  • 956f7e8e156205b8cbf9b9f16bae0e43404641ad8feaaf5f59f8ba7c54f15e24
  • 6022fd372dca7d6d366d9df894e8313b7f0bd821035dd9fa7c860b14e8c414f2
  • 517876386d6e68d72f5c89eb99e432dc7a592cc32478d0373193000d7dc88fc7
  • 104428a78aa75b4b0bc945a2067c0e42c8dfd5d0baf3cb18e0f6e4686bdc0755
  • da3c6ec20a006ec4b289a90488f824f0f72098a2f5c2d3f37d7a2d4a83b344a0
  • log.appsuites.ai

Attack Patterns