Projextor is a Trojanized productivity application that disguises itself as legitimate software, making it easy for users to trust and download without realizing they contain hidden malicious code. This threat campaign leverages the popularity of free productivity tools, which are often trusted by users who download them from websites with high-ranking search results. The malware uses Electron-based applications such as Kitchen Canvas, Food Formula, DocConvertWizard, and other PDF conversion tools under different names, each concealing the same malware beneath a working user interface.
The applications silently gain the ability to dynamically execute injected scripts and access desktop capture functionality through Electron APIs. To facilitate communication between the Chromium renderer process and privileged a script payload functionality, Electron uses a component known as a preload script. Executed before the renderer process is fully initialized, the preload script serves as a bridge between the browser environment and a script payload APIs, enabling application developers to selectively expose privileged functionality to web content.[/subscribe_to_unlock_form]
Projextor is a Trojanized productivity application that disguises itself as legitimate software, making it easy for users to trust and download without realizing they contain hidden malicious code. This threat campaign leverages the popularity of free productivity tools, which are often trusted by users who download them from websites with high-ranking search results. The malware uses Electron-based applications such as Kitchen Canvas, Food Formula, DocConvertWizard, and other PDF conversion tools under different names, each concealing the same malware beneath a working user interface.
The applications silently gain the ability to dynamically execute injected scripts and access desktop capture functionality through Electron APIs. To facilitate communication between the Chromium renderer process and privileged a script payload functionality, Electron uses a component known as a preload script. Executed before the renderer process is fully initialized, the preload script serves as a bridge between the browser environment and a script payload APIs, enabling application developers to selectively expose privileged functionality to web content.[emaillocker id="1283"]
The applications are not fake; they do what they promise to do. The concern is that they also include functionality that allows additional JavaScript code to be loaded and executed at runtime, giving the application capabilities far beyond those expected of a productivity tool. These applications are part of the same campaign or were built from the same code base, but it is unclear if they were created or operated by the same threat actor.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Execution | T1059.007 | Command and Scripting Interpreter | JavaScript |
| Execution | T1204.002 | User Execution | Malicious File |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Collection | T1113 | Screen Capture | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Execution | E1204 | User Execution |
| Defense Evasion | B0029 | Polymorphic Code |
| Anti-Behavioral Analysis | B0003 | Dynamic Analysis Evasion |
| Discovery | E1082 | System Information Discovery |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
| Execution | B0023 | Install Additional Program |
The following reports contain further technical details:
[/emaillocker]