💻🥷 WarthogTK 🩺 리트윗함

Dear security community/researchers, I'd really like to call to look at this x.com/greglesnewich/…, this information shows that the threat actors behind this Adobe Reader 0day attack was not just collecting local information but was really delivering additional exploits, need more analysis to figure out what the exploit really is. I'm one person and not have enough time to working on all the things..
Another earlier sample found today (virustotal.com/gui/file/54077…), which appeared on VT on 2025-11-28, shows that this APT campaign has been ongoing for at least 5 months, showing how serious this threat is.
#pdf #zeroday #0day #threatintel #apt
Greg Lesnewich@greglesnewich
@HaifeiLi Also, the original sample you found has a PCAP on VT that gets a cipher text payload but not the key :( Uploaded traffic here: gist.github.com/g-les/05f6edd8…
English



































