Threats Tagged 'suspicious behavior'
View all threats tagged with 'suspicious behavior'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'suspicious behavior'
Click on any threat for detailed analysis and mitigation recommendations
Since November 19, 2025, a suspicious PDF editor named 'ConvertMate' has been identified as a malicious vector infiltrating environments. Although it appears as a legitimate PDF converter, it performs unauthorized external connections, host queries, and creates artifacts indicative of compromise. It executes a PowerShell script that installs a scheduled task to repeat its malicious behavior every 24 hours. This activity closely resembles the earlier 'PDFEditor' campaign, with both files signed by the same entity, suggesting a coordinated threat actor. Immediate isolation and removal of 'ConvertMate' and related artifacts are critical. End-user training to recognize suspicious files and ads is also recommended. The threat does not require user interaction beyond initial download and installation, and no known exploits are publicly reported yet. The medium severity reflects its persistence and stealth but limited current exploitation scope. Join the discussion | AlienVault OTX General | 11/21/2025, 03:21:28 UTC Added: 11/21/2025, 09:37:19 UTC |
Showing 1 to 1 of 1 result