In late September 2025, Microsoft uncovered a malicious campaign involving a fake PDF editor called Crystal PDF, distributed through deceptive online ads and SEO poisoning. The installer, CrystalPDF.exe, functions as an infostealer that harvests browser credentials and exfiltrates sensitive data to attacker controlled domains.
The campaign primarily impacted organizations in the United States, especially within the education sector. With attackers abusing trusted platforms like Google Ads to distribute malware disguised as legitimate tools, this activity highlights the growing risk of malvertising and the importance of layered endpoint and identity protection.
Microsoft tracked a financially motivated campaign distributing a counterfeit PDF utility branded as Crystal PDF. The attackers leveraged search-engine manipulation and sponsored advertisements to promote the fake application as a legitimate document converter, increasing the likelihood of user interaction.
Behind the appearance of a productivity tool, the delivered binary CrystalPDF.exe operates as credential-stealing malware designed to harvest browser-stored authentication data. Harvested credentials and session tokens are transmitted to attacker-controlled infrastructure for potential account takeover and further exploitation.
The campaign disproportionately affected U.S. educational institutions, demonstrating how socially engineered software downloads can serve as an effective entry point into enterprise environments.
Technical
Analysis
Initial Access
Users trying to download the Crystal PDF tool from crystalpdf[.]com were instead redirected to attacker-controlled websites, receiving a malicious payload (CrystalPDF.exe) rather than a legitimate application. The campaign used a mix of social engineering and technical redirection to deliver malware while making the tool appear trustworthy.
Key details of the campaign include:
Malicious hosting domains:
smartdwn[.]com
seranlo[.]com
novarion[.]net (linked to multiple malvertising campaigns)
Deceptive ad delivery: The campaign relied on Google Ads to lure users to the fake PDF tool.
URL tracking parameters used by attackers:
utm_source – identifies where traffic originated
gad_campaignid – tracks the ad campaign that generated clicks
gclid – a unique click identifier for tracking ad performance
Automatic redirection: JavaScript (variables.js) hosted on crystalpdf[.]com silently redirected visitors to the malicious domains, delivering the credential-stealing malware while maintaining the tool’s legitimate appearance.
This combination of deceptive ads, tracking, and automated redirection allowed attackers to target users efficiently and collect sensitive data without raising suspicion.
Figure 1: Screenshot of cystalpdf[.]com showing “Free Download” button that downloads the CrystalPDF.exe payload
Figure 2: Another view of the Crystal PDF tool used to fool unsuspecting users
Figure 3: Digital certificate information from a CrystalPDF sample
Figure 4: JavaScript file, variables.js, hosted on cystalpdf[.]com that redirects the download of CrystalPDF.exe from seranlo[.]com
Execution and Persistence
Once executed, CrystalPDF.exe:
Copies itself to AppData\Local\Temp\crys
Creates a scheduled task named Crystal_updater
Configures daily execution at 7:15 AM local time
Drops a second executable, Crystal PDF.exe, to the Desktop
To maintain persistence, the malware creates a scheduled task that executes the following command every day: C:\Users\\AppData\Local\Temp\crys\CrystalPDF.exe update
Command & Control and Data Exfiltration
Upon execution, the malware initiates outbound connections to the following C2 domains:
strongdwn[.]com
negmari[.]com
ramiort[.]com
The payload CrystalPDF.exe targets Chrome and Firefox browsers, harvesting:
Stored credentials
Session cookies
Authentication tokens
Browser profile data from AppData\Roaming
This enables potential account takeover and impersonation of legitimate users.
The secondary executable, Crystal PDF.exe, connects to legitimate CloudConvert-related domains and appears to function as a decoy to maintain the illusion of a legitimate PDF tool.
Indicators of Compromise (IOCs)
Indicator Type
Value
Description
Domain
strongdwn[.]com
Command-and-control server used by the malware
Domain
negmari[.]com
Command-and-control infrastructure
Domain
ramiort[.]com
Command-and-control infrastructure
Domain
crystalpdf[.]com
Fake PDF tool distribution site
Domain
smartdwn[.]com
Malware delivery infrastructure
Domain
seranlo[.]com
Redirect domain hosting malicious payload
Domain
novarion[.]net
Domain associated with malvertising campaigns
File Name
CrystalPDF.exe
Primary credential-stealing malware payload
File Name
Crystal PDF.exe
Secondary decoy executable used to mimic legitimate software
Security analysts can correlate process activity with network connections to known command-and-control (C2) domains to identify potentially compromised devices. A sample approach is:
Enable cloud-delivered protection and real-time antivirus scanning.
Run EDR in block mode to automatically prevent malicious processes.
Enable network and web protection features in endpoint security platforms.
Educate users to avoid storing credentials in browsers or personal vaults.
Enforce multi-factor authentication (MFA) on all accounts.
Apply attack surface reduction rules:
Block executables from untrusted sources.
Restrict scheduled tasks that launch unknown binaries.
Detection
Risk Notes
Security teams can detect activity associated with this campaign using endpoint protection platforms and XDR telemetry by monitoring malware execution, suspicious network connections, and persistence mechanisms created on infected systems.
Microsoft DefenderAntivirus
Microsoft Defender Antivirus may detect the malware components using the following signatures:
Trojan:MSIL/Malgent
Trojan:MSIL/Stealer
These detections identify the malicious Crystal PDF payload during execution or file scanning.
Microsoft Defender for Endpoint Security alerts and telemetry that may indicate related activity include:
Suspicious outbound network connections to external domains associated with the campaign
Executables downloaded from untrusted or newly registered domains
Creation of unexpected scheduled tasks (e.g., Crystal_updater)
Execution of binaries from temporary directories such as AppData\Local\Temp
Correlating these indicators with network activity and process execution can help identify potentially compromised endpoints.
Remediation
Mapping
Steps to contain and eradicate the threat:
Isolate affected systems to prevent lateral movement.
Delete malicious files: CrystalPDF.exe in Temp folder, Crystal PDF.exe on Desktop.
Remove scheduled tasks associated with the malware (Crystal_updater).
Block malicious domains at network/firewall level.
Reset credentials for affected accounts and enforce MFA.
Run endpoint scans to verify removal of all malware components.
Trends &
Impact
This campaign aligns with tactics observed in the EvilAI campaign: masquerading as legitimate apps, using SEO and ad manipulation, and stealing browser credentials.
Educational institutions in the United States appear to be primary targets.
Similar campaigns may expand globally as attackers continue abusing malvertising and legitimate cloud services to evade detection.
Impacted
Technologies
Endpoints: Windows systems where the malicious CrystalPDF.exe installer was executed.
Browsers: Chrome and Firefox profiles targeted for credential and session token theft.
Identity & Cloud Services: Potential secondary impact if stolen browser sessions contain active authentication tokens for services such as Microsoft 365 or other SaaS platforms.
Why This Is
Important
This campaign highlights how easily trusted business tools and advertising platforms can be abused to deliver credential stealing malware into enterprise environments. Because the payload targets stored browser credentials and session tokens, attackers may gain unauthorized access to corporate email, cloud services, and internal systems without immediately triggering traditional security alerts.
For organizations, the impact goes beyond a single infected device. Stolen credentials can lead to data breaches, account takeover, business disruption, and potential regulatory or compliance exposure, especially in sectors like education that handle sensitive personal information. This activity reinforces the importance of defense in depth, strong identity protection controls, and continuous endpoint monitoring to reduce both operational and reputational risk.
How Wizard Cyber Can Help
Important
TTP-Driven Hunts
We run recurring, behavior-based hunts designed to catch malicious activity.
Unstructured Monthly Hunts
Each month we investigate emerging campaigns and emerging CVE frameworks, document what we find, and advise on next steps.
Yara specialises in proactive threat hunting, security awareness, and cyber security education. She combines technical threat analysis with user-focused security initiatives to help organisations strengthen their overall cyber resilience. She holds Microsoft SC-200, AZ-500, and SC-300 certifications
Certifications: SC-200, AZ-500, SC-300
Threat Hunting Team
The Threat Hunting Team at Wizard Cyber is focused on proactively seeking out advanced threats that evade traditional security measures. Leveraging advanced analytics and deep knowledge of threat actor behavior, they uncover hidden risks within our clients' environments. This team's continuous monitoring and analysis ensure that any potential compromises are detected and neutralized before they escalate.