Hackers Use Fake PDF Conversion Sites to Spread Malware: CloudSEK Uncovers Threat

Millions rely on free PDF-to-DOCX converters for quick file format changes—but cybercriminals are now exploiting this convenience. According to cybersecurity firm CloudSEK, malicious actors are creating counterfeit file conversion websites that mimic legitimate platforms to deploy data-stealing malware.

The attack, revealed shortly after a warning from the FBI, involves fake websites that closely resemble trusted services such as pdfcandy.com. These lookalike domains—like candyxpdf.com and candyconverterpdf.com—replicate official branding and user interfaces, including logos and animated progress indicators, to deceive users.

Once users attempt to convert a PDF file, they’re presented with a captcha screen to further build trust. However, the danger lies just beyond this point. Victims are prompted to execute a PowerShell command that downloads a malicious ZIP file named adobe.zip. Inside is ArechClient, a trojan linked to the SectopRAT family—active since 2019 and capable of harvesting browser credentials, crypto wallet data, and other sensitive information.

Though some of these malicious sites have been removed, they reportedly attracted over 6,000 visits last month alone—highlighting the effectiveness of the ruse and the widespread risk it poses.

How to Protect Yourself:

  • Verify URLs: Always double-check domain names to ensure you’re using the official website.
  • Avoid Suspicious Prompts: Never run system commands or download files prompted by online tools.
  • Use Offline Alternatives: For sensitive documents, use trusted offline software to handle file conversions.
  • React Quickly: If you suspect infection, disconnect affected devices and change all important passwords immediately.

As digital tools become more widespread, it’s crucial to stay vigilant against evolving cyber threats disguised as everyday utilities.

 

- Advertisement -

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles

error: Content is protected !!

Sign Up for CXO Digital Pulse Newsletters

Sign Up for CXO Digital Pulse Newsletters to Download the Research Report

Sign Up for CXO Digital Pulse Newsletters to Download the Coffee Table Book

Sign Up for CXO Digital Pulse Newsletters to Download the Vision 2023 Research Report

Download 8 Key Insights for Manufacturing for 2023 Report

Sign Up for CISO Handbook 2023

Download India’s Cybersecurity Outlook 2023 Report

Unlock Exclusive Insights: Access the article

Download CIO VISION 2024 Report

Share your details to download the report

Share your details to download the CISO Handbook 2024

Fill your details to Watch