Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Projextor: Abusing Electron in Trojanized Productivity Applications

0
Medium
Published: 08/17/2026 (08/17/2026, 15:16:22 UTC)
Source: AlienVault OTX General

Description

Projextor is a malware campaign that abuses Electron-based productivity applications to deliver malicious payloads. It masquerades as legitimate tools such as document converters and meal planners, distributed via impersonation websites that rank highly in search results. The malware uses insecure Electron configurations allowing dynamic JavaScript execution and desktop capture. Infection starts with installers that download the main Electron app, which uses preload scripts to exploit privileged Node.js APIs with disabled security features. This enables arbitrary code execution, screen monitoring, and remote command execution while maintaining a functional user interface to avoid suspicion.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/18/2026, 10:55:06 UTC

Technical Analysis

Projextor is a malware campaign leveraging trojanized Electron-based productivity applications like Kitchen Canvas, Food Formula, DocConvertWizard, and PDFGrip. These applications have insecure Electron configurations that permit dynamic JavaScript execution and desktop capture capabilities. The infection chain begins with NSIS, Squirrel, or Inno Setup installers that download the main Electron application. Preload scripts abuse privileged Node.js APIs with intentionally disabled security features, enabling arbitrary code execution and screen monitoring. Distribution is via impersonation websites mimicking legitimate services, using high-ranking search results to lure victims. The malware captures sensitive information, monitors user activity, and executes remote commands while maintaining the appearance of legitimate functionality.

Potential Impact

The malware enables threat actors to execute arbitrary code on the victim's system, capture screen content, monitor user activity, and execute remote commands. This compromises sensitive information and user privacy while maintaining a facade of legitimate application functionality, increasing the likelihood of prolonged undetected presence.

Defensive Guidance

No official patch or remediation guidance is provided. Users should avoid downloading Electron-based productivity applications from untrusted sources or impersonation websites. Employ application whitelisting and verify software authenticity before installation. Monitor for suspicious installer behaviors such as unexpected network downloads. Since this is a malware campaign abusing insecure Electron configurations, developers should ensure secure Electron app configurations and disable privileged Node.js API access in preload scripts.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://blog.gdatasoftware.com/2026/08/38468-projextor-abusing-electron"]
Adversary
null
Pulse Id
6a8325c63ec6c1f8d93275f6
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainpdfgrip.com
domaindoceditor.in
domaindoceditorinc.com
domainflipformatpdf.com
domainmeal-formula.com
domainconv.doceditorinc.com

Hash

ValueDescriptionCopy
hashd749e0f8f2cd4e14178a787571534121
hash04cc663812883562b762d184266e1457e98b7de8
hash3c1dbc3f56e91cc79f0014850e773a7f12bbfef06680f08f883b2bf12873eccc
hash415a96f247ec0477080f576a4b91f7a1
hash973c9e55811bf4940a874d3b6e6e2e0c
hashb648ec0880e9f5421fdb380e620b6173
hashbb389838978c45391288979ae6c634e61aa61448
hashe387f61298206d5e538fafb5f0f83b5ea72959f8
hashf7a060bc408acfb14ce59e40710b630291c76540
hash4ce5e5768d2f9f71e2835ab8ebc4a2191d436ca3a990a56e9bc264235c7b5b55
hash71656539cc644513396f56100ffb56f9ef9eaa5b7a16b0773d6e5d370a912a88
hasha799417bd79060d63e93682f339fbe2868de3881f9c5865d9b583f5b715c70a9
hashc21eb14ba63e943db5ea9ab64af02a50a17260c7d8538a133c4f6e0957d36f47
hashd50ca2fa212df1c1ff69b5d26ba594bd39bfd86a71b068a650cc577e5dc9a94e
hashe7bc36c7345b3894bc1da3d18ff3dbf0a20713d17b93a585ac0da65776d29027

Url

ValueDescriptionCopy
urlhttps://flipformatpdf.com/
urlhttps://kitchen-canvas.com/
urlhttps://pdfgrip.com/
urlhttps://conv.doceditorinc.com/latest/part
urlhttps://doceditor.in
urlhttps://doceditorinc.com
urlhttps://doceditorinc.com/
urlhttps://meal-formula.com/

Threat ID: 6a842553bf8831d53988213e

Added to database: 08/18/2026, 09:26:43 UTC

Last enriched: 08/18/2026, 10:55:06 UTC

Last updated: 08/18/2026, 10:55:06 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses