#pdf — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #pdf, aggregated by home.social.
-
How Organizations Use AI: Evidence from ChatGPT [pdf]
https://cdn.openai.com/pdf/how-organizations-use-chatgpt.pdf
Comments: https://news.ycombinator.com/item?id=49290768
#HackerNews #AI #Organizations #ChatGPT #Evidence #PDF #Technology
-
How Organizations Use AI: Evidence from ChatGPT [pdf]
https://cdn.openai.com/pdf/how-organizations-use-chatgpt.pdf
Comments: https://news.ycombinator.com/item?id=49290768
#HackerNews #AI #Organizations #ChatGPT #Evidence #PDF #Technology
-
China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business
Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.
Pulse ID: 6a7da6cbe879002fadce7e53
Pulse Link: https://otx.alienvault.com/pulse/6a7da6cbe879002fadce7e53
Pulse Author: AlienVault
Created: 2026-08-13 11:13:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Chrome #Cookies #CyberSecurity #Email #Espionage #FireFox #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #bot #cryptocurrency #AlienVault
-
China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business
Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.
Pulse ID: 6a7da6cbe879002fadce7e53
Pulse Link: https://otx.alienvault.com/pulse/6a7da6cbe879002fadce7e53
Pulse Author: AlienVault
Created: 2026-08-13 11:13:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Chrome #Cookies #CyberSecurity #Email #Espionage #FireFox #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #bot #cryptocurrency #AlienVault
-
APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.
Pulse ID: 6a7daa9c80273555f3d3ccd1
Pulse Link: https://otx.alienvault.com/pulse/6a7daa9c80273555f3d3ccd1
Pulse Author: AlienVault
Created: 2026-08-13 11:29:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Cookies #CyberSecurity #Espionage #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #Webmail #bot #cryptocurrency #AlienVault
-
APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.
Pulse ID: 6a7daa9c80273555f3d3ccd1
Pulse Link: https://otx.alienvault.com/pulse/6a7daa9c80273555f3d3ccd1
Pulse Author: AlienVault
Created: 2026-08-13 11:29:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Cookies #CyberSecurity #Espionage #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #Webmail #bot #cryptocurrency #AlienVault
-
Versión 2.14.3 de Stirling PDF, potente plataforma de edición de PDF de código abierto para Windows, macOS y Linux: https://www.dekazeta.net/foro/files/file/5190-stirling-pdf/
-
Versión 2.14.3 de Stirling PDF, potente plataforma de edición de PDF de código abierto para Windows, macOS y Linux: https://www.dekazeta.net/foro/files/file/5190-stirling-pdf/
-
Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Indicators extracted from public reporting. Source: https://sed-cms.broadcom.com/sites/default/files/2026-08/Jewelbug%20Dossier.pdf
Pulse ID: 6a7da2dc1ab7ab31faf83152
Pulse Link: https://otx.alienvault.com/pulse/6a7da2dc1ab7ab31faf83152
Pulse Author: CyberHunter_NL
Created: 2026-08-13 10:56:27Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DoS #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #RAT #RCE #bot #CyberHunter_NL
-
Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Indicators extracted from public reporting. Source: https://sed-cms.broadcom.com/sites/default/files/2026-08/Jewelbug%20Dossier.pdf
Pulse ID: 6a7da2dc1ab7ab31faf83152
Pulse Link: https://otx.alienvault.com/pulse/6a7da2dc1ab7ab31faf83152
Pulse Author: CyberHunter_NL
Created: 2026-08-13 10:56:27Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DoS #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #RAT #RCE #bot #CyberHunter_NL
-
State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit
North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.
Pulse ID: 6a7d8b5671a34dd89301bbbe
Pulse Link: https://otx.alienvault.com/pulse/6a7d8b5671a34dd89301bbbe
Pulse Author: AlienVault
Created: 2026-08-13 09:16:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault
-
State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit
North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.
Pulse ID: 6a7d8b5671a34dd89301bbbe
Pulse Link: https://otx.alienvault.com/pulse/6a7d8b5671a34dd89301bbbe
Pulse Author: AlienVault
Created: 2026-08-13 09:16:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault
-
Master Hsu Yun (虚云) A Brief Biography By Upasaka Lu K’uan Yu – THE MOUNTAIN PATH / Vol. 1 – OCTOBER 1964
Hsu-Yun_Dharma-WordsHerunterladen #1964 #ABriefBiography #Dharma #HsuYun #LuKUanYü #PDF #Zen -
PDF magazine: Pitstop Retro, issue 2
By issue 8/2026, the second release of the PDF magazine Pitstop Retro has been published, a free gaming magazine for C64 and Amiga. Topics include "The Adventure of Node", "Eclipse", "Rex: Into the Shadow Realm" and "The Voyage of the Beano", among others.
-
PDF magazine: Pitstop Retro, issue 2
By issue 8/2026, the second release of the PDF magazine Pitstop Retro has been published, a free gaming magazine for C64 and Amiga. Topics include "The Adventure of Node", "Eclipse", "Rex: Into the Shadow Realm" and "The Voyage of the Beano", among others.
-
@mos_8502 I have another script that creates a PDF of qrcodes... Encrypted files encoded to codegroup-qrcodes that you can store in a drawer... or laser etch onto something.
-
@mos_8502 I have another script that creates a PDF of qrcodes... Encrypted files encoded to codegroup-qrcodes that you can store in a drawer... or laser etch onto something.
-
PSA: EPUBs are better than PDFs!
I saw some misinformation and had a rant that calmed down into a PSA lol.
https://blog.pomnavi.net/posts/0029-psa-epubs-are-better-than-pdfs/
-
We're replacing the browser print dialog for PDF-creation with something better for Fidus Writer 5.0.
New PDF exporter demo (Vivliostyle + PDF-lib):
→ CSS-based page layout
→ Crop marks & custom metadata
→ Source document embedding
→ 100% browser-based = E2E encryption friendlyhttps://fiduswriter.github.io/vivliostyle-pdf/
What PDF output features are missing from your current workflow?
-
We're replacing the browser print dialog for PDF-creation with something better for Fidus Writer 5.0.
New PDF exporter demo (Vivliostyle + PDF-lib):
→ CSS-based page layout
→ Crop marks & custom metadata
→ Source document embedding
→ 100% browser-based = E2E encryption friendlyhttps://fiduswriter.github.io/vivliostyle-pdf/
What PDF output features are missing from your current workflow?
-
«Versteckter Text in einem PDF reicht aus, um über Atlassians KI-Agent Rovo sensible Daten zu stehlen:
Atlassians KI-Agent Rovo ist anfällig für eine sogenannte indirekte Prompt Injection, die es Angreifern ermöglicht, sensible Unternehmensdaten aus Jira-Tickets und Confluence-Dokumenten abzugreifen.»Ich lasse das mal hier so stehen…
#pdf #ki #daten #sensibel #rovo #text #verstecken #injection #dokument #jira #itsicherheit #jiratickets
-
«Versteckter Text in einem PDF reicht aus, um über Atlassians KI-Agent Rovo sensible Daten zu stehlen:
Atlassians KI-Agent Rovo ist anfällig für eine sogenannte indirekte Prompt Injection, die es Angreifern ermöglicht, sensible Unternehmensdaten aus Jira-Tickets und Confluence-Dokumenten abzugreifen.»Ich lasse das mal hier so stehen…
#pdf #ki #daten #sensibel #rovo #text #verstecken #injection #dokument #jira #itsicherheit #jiratickets
-
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Indicators extracted from public reporting. Source: https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF
Pulse ID: 6a79ace8ce2eec075b55ddb0
Pulse Link: https://otx.alienvault.com/pulse/6a79ace8ce2eec075b55ddb0
Pulse Author: CyberHunter_NL
Created: 2026-08-10 10:50:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RCE #Russia #Zimbra #bot #CyberHunter_NL
-
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Indicators extracted from public reporting. Source: https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF
Pulse ID: 6a79ace8ce2eec075b55ddb0
Pulse Link: https://otx.alienvault.com/pulse/6a79ace8ce2eec075b55ddb0
Pulse Author: CyberHunter_NL
Created: 2026-08-10 10:50:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RCE #Russia #Zimbra #bot #CyberHunter_NL
-
I want to get rid of all these paper manuals.
Either download or maybe scan and then some folder to archive.
Is there something less complex than paperless to access/manage them with a Web UI?
I have paperless for important documents, but there is no need to have advanced features. Just folders and maybe tags should be sufficient.
#pdf #archive #archiving #opensource #dumpster #docker #selfhosting -
Can you recommend Linux tools for extracting the text of scanned, OCRed PDFs?
-
Can you recommend Linux tools for extracting the text of scanned, OCRed PDFs?
-
De ce que j'ai lu, Framasoft PDF n'a pas le certificat de conformité eIDAS.
En tout cas, ils n'en font pas mention.En cherchant autour de [eIDAS], j'ai trouvé ça :
https://aidocx.ai/fr/blog/best-free-esignature-software-2026mais ça ne va pas très loin.
Va falloir fouiller, je pense et veiller aux certifications.
#EIDAS #Signature #PDF🐞
-
De ce que j'ai lu, Framasoft PDF n'a pas le certificat de conformité eIDAS.
En tout cas, ils n'en font pas mention.En cherchant autour de [eIDAS], j'ai trouvé ça :
https://aidocx.ai/fr/blog/best-free-esignature-software-2026mais ça ne va pas très loin.
Va falloir fouiller, je pense et veiller aux certifications.
#EIDAS #Signature #PDF🐞
-
Investigating Power-Confluent Drawings for Network Visualization https://lobste.rs/s/ljwatd #pdf #visualization
https://arxiv.org/pdf/1810.09948 -
Investigating Power-Confluent Drawings for Network Visualization https://lobste.rs/s/ljwatd #pdf #visualization
https://arxiv.org/pdf/1810.09948 -
Some Moral and Technical Consequences of Automation (1960) https://lobste.rs/s/rgzoku #pdf #philosophy
https://www.cs.umd.edu/users/gasarch/BLOGPAPERS/moral.pdf -
Some Moral and Technical Consequences of Automation (1960) https://lobste.rs/s/rgzoku #pdf #philosophy
https://www.cs.umd.edu/users/gasarch/BLOGPAPERS/moral.pdf -
Fake PDFs and Chat Apps Let Patchwork Spy on PCs and Android Phones
Indicators extracted from public reporting. Source: https://www.picussecurity.com/resource/blog/dropping-elephant-patchwork-espionage-apt-tactics-and-tools
Pulse ID: 6a75c7e5ba5f5ced0fa6825a
Pulse Link: https://otx.alienvault.com/pulse/6a75c7e5ba5f5ced0fa6825a
Pulse Author: CyberHunter_NL
Created: 2026-08-07 11:56:21Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #CyberSecurity #Espionage #HTTP #HTTPS #ICS #InfoSec #OTX #OpenThreatExchange #PDF #RCE #bot #CyberHunter_NL
-
Fake PDFs and Chat Apps Let Patchwork Spy on PCs and Android Phones
Indicators extracted from public reporting. Source: https://www.picussecurity.com/resource/blog/dropping-elephant-patchwork-espionage-apt-tactics-and-tools
Pulse ID: 6a75c7e5ba5f5ced0fa6825a
Pulse Link: https://otx.alienvault.com/pulse/6a75c7e5ba5f5ced0fa6825a
Pulse Author: CyberHunter_NL
Created: 2026-08-07 11:56:21Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #CyberSecurity #Espionage #HTTP #HTTPS #ICS #InfoSec #OTX #OpenThreatExchange #PDF #RCE #bot #CyberHunter_NL
-
Cześć Mamuciska!
Znajoma osoba pracująca w jednym z urzędów o ogólnopolskim zasięgu niedawno otrzymała e-mail z informacją o tym, że wkrótce z komputerów służbowych zostanie odinstalowany Adobe Acrobat, gdyż... zajmuje zbyt dużo miejsca na dysku i potrzebuje do działania zbyt dużo RAM-u. Dziwne, że dopiero teraz zaczęło to przeszkadzać. Czy rzeczywiście jest tak zasobożerny?
Zatem jak odtąd będą przeglądać PDF-y? Ano kierownictwo zaleciło otwierać je za pomocą... przeglądarek. Do wyboru Edge lub Chrome. Czy dane z tych dokumentów są narażone w nich na ,,podgląd" z Sieci? Czy to niesie ze sobą ryzyko ich wycieku?#AdobeAcrobat #PDF #przeglądarka #Edge #Chrome #bezpieczeństwodanych
-
Cześć Mamuciska!
Znajoma osoba pracująca w jednym z urzędów o ogólnopolskim zasięgu niedawno otrzymała e-mail z informacją o tym, że wkrótce z komputerów służbowych zostanie odinstalowany Adobe Acrobat, gdyż... zajmuje zbyt dużo miejsca na dysku i potrzebuje do działania zbyt dużo RAM-u. Dziwne, że dopiero teraz zaczęło to przeszkadzać. Czy rzeczywiście jest tak zasobożerny?
Zatem jak odtąd będą przeglądać PDF-y? Ano kierownictwo zaleciło otwierać je za pomocą... przeglądarek. Do wyboru Edge lub Chrome. Czy dane z tych dokumentów są narażone w nich na ,,podgląd" z Sieci? Czy to niesie ze sobą ryzyko ich wycieku?#AdobeAcrobat #PDF #przeglądarka #Edge #Chrome #bezpieczeństwodanych
-
New freeCodeCamp article 📄
How to build a browser-based PDF Color Inverter with JavaScript—fast, private, and no backend required.
https://www.freecodecamp.org/news/build-pdf-color-inverter-tool-javascript/
-
Vulnerability in ngx-extended-pdf-viewer (HIGH): Bundled pdf.js exposes XFA (enabled by default), risking JS execution via malicious PDFs (CVE-2026-16633). Update to 29.0.0-rc.3 or disable XFA for mitigation. https://radar.offseq.com/threat/ngx-extended-pdf-viewer-bundles-a-version-of-pdfjs-vulnerable-to-cve-2026-16633-3a7320cdbeb0cda3 #OffSeq #Vulnerability #PDF #Infosec
-
TONTOU: On the Exploitability of Time-of-Neutralization to Time-of-Use Windows https://lobste.rs/s/eodvvq #pdf #security
https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf -
TONTOU: On the Exploitability of Time-of-Neutralization to Time-of-Use Windows https://lobste.rs/s/eodvvq #pdf #security
https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf -
A Polynomial-Time Quantum Algorithm for the Dihedral Coset Problem https://lobste.rs/s/mfylx2 #pdf #cryptography
https://eprint.iacr.org/2026/1591.pdf -
A Polynomial-Time Quantum Algorithm for the Dihedral Coset Problem https://lobste.rs/s/mfylx2 #pdf #cryptography
https://eprint.iacr.org/2026/1591.pdf -
Fake CAPTCHA, Real Business: Traffic Distribution for Hire
A sophisticated traffic distribution system has been operating for over 14 months, using more than 12,700 structurally similar fake CAPTCHA PDFs hosted on Webflow's CDN. The operation begins with search engine optimization, where victims searching for legitimate content encounter malicious PDFs through Google searches. These documents contain fake CAPTCHA panels that route users through a custom Elixir/Phoenix traffic distribution system employing IP filtering, bot detection, and geographic targeting. The infrastructure sorts visitors and redirects qualifying traffic to three distinct endpoints: Legion Loader distribution, a TDS reseller gate, and premium-SMS subscription scams targeting Spanish-speaking users. Non-qualifying traffic is monetized through search-arbitrage advertising. The operation primarily targets English-speaking countries and has recently been surfaced by AI assistants including Google Gemini and Claude, expanding its reach beyond traditional search engines.
Pulse ID: 6a734a570822e0edf4d1fdb5
Pulse Link: https://otx.alienvault.com/pulse/6a734a570822e0edf4d1fdb5
Pulse Author: AlienVault
Created: 2026-08-05 14:36:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #CDN #CyberSecurity #Endpoint #Google #InfoSec #OTX #OpenThreatExchange #PDF #RAT #SMS #bot #AlienVault
-
Fake CAPTCHA, Real Business: Traffic Distribution for Hire
A sophisticated traffic distribution system has been operating for over 14 months, using more than 12,700 structurally similar fake CAPTCHA PDFs hosted on Webflow's CDN. The operation begins with search engine optimization, where victims searching for legitimate content encounter malicious PDFs through Google searches. These documents contain fake CAPTCHA panels that route users through a custom Elixir/Phoenix traffic distribution system employing IP filtering, bot detection, and geographic targeting. The infrastructure sorts visitors and redirects qualifying traffic to three distinct endpoints: Legion Loader distribution, a TDS reseller gate, and premium-SMS subscription scams targeting Spanish-speaking users. Non-qualifying traffic is monetized through search-arbitrage advertising. The operation primarily targets English-speaking countries and has recently been surfaced by AI assistants including Google Gemini and Claude, expanding its reach beyond traditional search engines.
Pulse ID: 6a734a570822e0edf4d1fdb5
Pulse Link: https://otx.alienvault.com/pulse/6a734a570822e0edf4d1fdb5
Pulse Author: AlienVault
Created: 2026-08-05 14:36:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #CDN #CyberSecurity #Endpoint #Google #InfoSec #OTX #OpenThreatExchange #PDF #RAT #SMS #bot #AlienVault
-
Yes, markdown, or *any* other format should be used, but basically, the PDF feels bloated, and it has some links that overlap, text seems jumbled, as in, like, suddenly on a new line, I am not sure if anyone is making you use PDFs but personally, PDF should be illegal, punishable with jail time and a hefty fine if someone *willingly* hands me a PDF, that is how much I hate PDFs and I will never understand why sighted folk love them. @Sobex #PDF
-
Versión 1.7.1 de KillerPDF, editor de PDF gratuito y de código abierto para Windows: https://www.dekazeta.net/foro/files/file/5114-killerpdf/