Fake PDF converters are spreading malware to steal user information and worse – here’s how to stay secure

- Fake PDF converters are tricking users with cloned sites and fake CAPTCHAs
- PowerShell command installs malware that steals browser and crypto wallet data
- Attackers use realistic designs and social engineering to avoid detection
Cybercriminals are using fake PDF converters to install powerful malware on victims’ systems, experts have warned.
Research from CloudSEK found attackers are cloning popular file conversion websites like pdfcandy.com – replicating its logo and brand elements – in order to trick users into downloading malicious software.
CloudSEK says these fake sites look almost identical to the real ones. When someone tries to convert a file, the page shows a fake loading screen and then prompts for a CAPTCHA verification. Instead of just confirming the user is human, this step leads to an instruction to run a PowerShell command. Following the command downloads a zip file containing malware known as ArechClient2, part of the SectopRAT family of information stealers.
Collecting personal data, and worse
The malware uses a number of hidden methods to infect the system. It spawns normal Windows processes to hide its activity and begins collecting browser passwords, crypto wallet information, and other sensitive data. Once the malware is active, it can quietly send stolen information back to the attackers, CloudSEK reports.
The FBI has already warned that online file converters are becoming a popular way for criminals to spread their malware. CloudSEK’s research shows that attackers are improving their methods, cleverly blending realistic website designs with social engineering tricks in order to lower users’ defenses.
With online tools becoming part of everyday work and personal life, it’s important to know how to avoid these threats.
How to stay safe
The best way to protect yourself is to avoid clicking random search results for online file converters. Always visit known official websites directly.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
In addition to that, always double-check the website address for small spelling changes that might be easy to miss.
For a good starting point, check out our round up of the best PDF editors, and the best free PDF editors. We also recommend the best Adobe Acrobat alternatives.
Staying cautious when uploading documents online can stop many of these attacks before they start.
Keep your antivirus software up to date (you’re doing this anyway, right?) and scan any downloaded files before you open them. Installing browser extensions that block suspicious or dangerous sites can also help.
If a website asks you to run PowerShell commands or download extra files after uploading a document, close the page immediately.
Finally, if you think you’ve been tricked, disconnect the device from the internet right away, change all important passwords from a safe device, and let your bank or service providers know as soon as possible.
You might also like
Fake PDF converters are tricking users with cloned sites and fake CAPTCHAs PowerShell command installs malware that steals browser and crypto wallet data Attackers use realistic designs and social engineering to avoid detection Cybercriminals are using fake PDF converters to install powerful malware on victims’ systems, experts have warned. Research…
Recent Posts
- Sony shows off the PS5 Pro’s liquid metal updates
- Fake PDF converters are spreading malware to steal user information and worse – here’s how to stay secure
- New AI Chibi figure trend may be the cutest one yet, and we’re all doomed to waste time and energy making these things
- Airbnb now shows the full price of your stay by default
- Bethesda confirms Oblivion remaster’s imminent reveal
Archives
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010