Risk actors behind the Projextor marketing campaign are abusing Electron-based productiveness purposes to hide malware-like capabilities behind absolutely functioning doc converters, meal planners, recipe instruments, and PDF utilities.
The purposes ship their marketed options, however their shared codebase additionally allows runtime JavaScript execution and entry to desktop-capture performance making a severe surveillance and post-compromise threat.
Search-optimized web sites and convincing obtain pages could make undesirable purposes seem respectable, notably after they supply frequent capabilities comparable to PDF conversion or doc modifying.
Comparable ways have been noticed within the TamperedChef marketing campaign, the place malicious PDF-editor software program was promoted by fraudulent web sites and operated as a backdoor beneath a decoy interface.
Researchers recognized a cluster of associated Electron purposes, together with Kitchen Canvas, Meals or Meal Method, DocConvertWizard, and several other PDF conversion utilities.
Regardless of differing names and claimed functions, the samples shared near-identical Electron framework parts, together with primary.js and preload.js, indicating that they seemingly originated from a standard improvement framework or marketing campaign infrastructure.
Projextor is distributed by web sites promoting doc conversion, recipe administration, and meal-planning purposes.
One noticed area, doceditorinc[.]com, seems designed to impersonate the respectable on-line document-processing service doceditor[.]in.
Such lookalike infrastructure may be particularly efficient when paired with search-engine visibility, as a result of victims could obtain the applying after looking for a routine software program utility.
The primary-stage installers range in format, with samples packaged utilizing NSIS, Squirrel Installer, and Inno Setup. No matter packaging, every acts as a downloader for a second-stage Electron utility.
The downloaded Electron package deal contained the important thing primary.js and preload.js parts liable for the applying’s privileged habits.
Electron combines Chromium and Node.js, permitting purposes constructed with HTML, CSS, and JavaScript to entry native desktop sources.
G Knowledge Researchers stated that, the marketing campaign displays a rising sample of abuse by which attackers exploit customers’ belief in free productiveness software program. Its preload-script mechanism is meant to bridge browser-renderer content material with privileged Node.js performance selectively.
Projextor’s An infection Method
Electron recommends isolating that bridge, as a result of context isolation prevents loaded net content material from immediately accessing Electron internals and privileged APIs.
Projextor’s code as a substitute explicitly makes use of contextIsolation: false. It is a notable crimson flag: context isolation has been enabled by default since Electron 12 and is a core safety suggestion for purposes that load net content material.
Disabling it will probably enable renderer-side content material to work together with APIs uncovered by the preload layer, considerably increasing the influence of compromised or attacker-controlled net content material.
The appliance additionally suppresses legacy-build warnings by disableOldBuildWarning, apparently stopping customers from being alerted to outdated and doubtlessly insecure Electron variations.
Extra importantly, the preload layer can find and execute JavaScript modules from a devoted injection listing.
This creates a modular execution mechanism by which operators may introduce new performance after set up with out changing the primary utility binary.
Projextor moreover implements a customized screen-share picker that enumerates accessible desktops and utility home windows, shows thumbnails, and selects a seize supply by Electron IPC communication.
The purposes are subsequently not easy faux utilities. They’re practical packages with embedded architectural decisions that let habits far past what customers would moderately anticipate from a PDF converter or meal-planning software.
Electron’s desktopCapturer API is respectable performance designed to acquire desktop media sources for seize by browser media APIs.
On this context, nevertheless, desktop enumeration mixed with dynamic script execution considerably raises the applying’s threat profile.
An operator may doubtlessly seize delicate paperwork, authentication prompts, browser periods, electronic mail content material, monetary information, or collaboration-platform exercise seen on a sufferer’s display.
Organizations ought to block the recognized infrastructure, hunt for the equipped hashes, and overview Electron purposes whose preload scripts disable isolation, load distant or injected JavaScript, or expose desktop-capture options with out a clear enterprise justification.
IOCs
| Hashes | G DATA Detection |
| A799417BD79060D63E93682F339FBE2868DE3881F9C5865D9B583F5B715C70A9 FlipFormat_610220.exe |
Win32.Malware.Projextor.EÂ |
| 71656539CC644513396F56100FFB56F9EF9EAA5B7A16B0773D6E5D370A912A88 PDFGrip_646990.exe  |
Win32.Malware.Projextor.EÂ |
| e7bc36c7345b3894bc1da3d18ff3dbf0a20713d17b93a585ac0da65776d29027 FoodFormula_822670.exe |
Win32.Malware.Projextor.EÂ |
| 3C1DBC3F56E91CC79F0014850E773A7F12BBFEF06680F08F883B2BF12873ECCC KitchenCanvas_748343.exe  |
Win32.Malware.Projextor.EÂ |
| D50CA2FA212DF1C1FF69B5D26BA594BD39BFD86A71B068A650CC577E5DC9A94E Preload.js |
Script.Malware.Projextor.B |
Notice: IP addresses and domains are deliberately defanged (e.g., [.]) to stop unintended decision or hyperlinking. Re-fang solely inside managed menace intelligence platforms comparable to MISP, VirusTotal, or your SIEM.
[Live Webinar] Be part of Elastic & UnderDefense to learn the way small safety groups can unify AI visibility and agentic response into one working mannequin. -> Register Now






