Skip to main content
JS
Jacob Santos

Jacob Santos

Threat Hunter, Researcher and Builder

Sr. Threat Researcher | Trend AI
17
Articles
14
Threads
10+
Tools
10+
Talks
PureRAT Campaign Targets Job Seekers, Abuses Foxit PDF Reader for DLL Side-loading
Trend AI Research Blog Dec 2025

PureRAT Campaign Targets Job Seekers, Abuses Foxit PDF Reader for DLL Side-loading

RATSocial EngineeringDLL Sideloading

This research uncovers a social engineering campaign deploying PureRAT through trojanized job application documents. The attackers rename legitimate Foxit PDF Reader binaries to load malicious DLLs, establishing persistent access through the PureRAT backdoor. The infection chain uses Python-based shellcode loaders to evade static analysis, with multi-stage payloads that check for analysis environments before proceeding. The campaign specifically targets job seekers, leveraging urgency and trust in PDF documents to achieve initial compromise. Includes detailed loader analysis, C2 protocol breakdown, and YARA rules for detection.