Securepdf viewer.app

Malware updated a month ago (2024-11-29T13:56:59.175Z)
Download STIX
Preview STIX
SecurePDF Viewer.app is a malicious software (malware) that has been found to exploit and potentially damage computer systems, particularly those running on macOS 12.6 (Monterey) or later versions. It infiltrates the system through suspicious downloads, emails, or websites, often unbeknownst to the user. Once inside, it can perform harmful activities such as stealing personal information, disrupting operations, or holding data hostage for ransom. The malware comes with the bundle identifier com.softwaredev.swift-ui-test, indicating its deceptive appearance as a legitimate application. The SecurePDF Viewer.app was initially distributed under the name "InternalPDF Viewer". However, in June, researchers identified a variant of this malware named SecurePDF Viewer.app. This variant was signed and notarized by Apple, providing it with an additional layer of perceived legitimacy. The developer associated with the application is "BBQ BAZAAR PRIVATE LIMITED (7L2UQTVP6F)". Apple has since revoked the notarization, acknowledging the malicious nature of the app. Our research further suggests that the SecurePDF Viewer.app might be a subsequent stage of another malware known as ObjCShellz. This indicates a possible evolution or advancement in the malicious software's capabilities and tactics. Users are advised to exercise caution when downloading applications and to regularly update their security software to protect against such threats.
Description last updated: 2024-01-06T12:18:37.549Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Securepdf viewer.app Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more