New MaaS Targets Windows Users with Adobe-Themed .bat Files
Key Takeaways A new Malware-as-a-Service (MaaS) platform, dubbed “Kaido Panel,” is actively targeting Windows users. The operation leverages an Adobe-themed domain,...
Key Takeaways
- A new Malware-as-a-Service (MaaS) platform, dubbed “Kaido Panel,” is actively targeting Windows users.
- The operation leverages an Adobe-themed domain, acrobatreaderonline.com, to trick victims into downloading malicious files.
- The MaaS platform offers features for data exfiltration, banking overlays, and payment fraud, lowering the barrier for cybercriminals.
- Initial infection often occurs via malicious .bat files delivered through WebDAV remote folders, exploiting the Windows WebClient service.
- Organizations and individual users are urged to block associated domains and monitor for suspicious WebClient activity.
A sophisticated criminal enterprise is operating a malicious service disguised as an Adobe Acrobat Reader download site. The domain, acrobatreaderonline.com, is not a legitimate document service but rather a malicious platform designed to facilitate attacks against Windows users. This Malware-as-a-Service (MaaS) operation capitalizes on the common tactic of using trusted-looking themes, such as document or payment lures, to trick unsuspecting victims into downloading harmful software.
Previous activity linked to the same malicious infrastructure involved the delivery of Windows batch (.bat) files through WebDAV remote folders. In these instances, what appeared to be a PDF or payment document (boleto) would serve as a deceptive entry point for malware. This method effectively transforms seemingly innocuous files into vectors for system compromise.
Security researchers at Clandestine uncovered this operation during an open-source investigation on August 23, 2026. They identified a fully functional MaaS control panel hosted on the Adobe-themed domain. Clandestine said in a report shared with Cyber Security News (CSN) that the website is not an authentic Adobe Reader portal and should be considered unsafe. The discovery highlights how a convincing brand impersonation can seamlessly transition from a phishing bait to a fully operational criminal platform, offering features like victim data collection, file management, and malware module deployment, thereby lowering the barrier for potential attackers.
https://t.co/LaGothWxgV is not Adobe Acrobat Reader Online.
Open-source review on 23 August 2026 shows a live malware-as-a-service panel behind an Adobe-themed domain. The page title is SecureWorkspace WebPanel; /api/ renders as Kaido Panel. The stack is Vite/React, Tailwind… pic.twitter.com/arJGRFqXto
New Malware-as-a-service Leveraging Adobe-themed Domain
The deceptive domain poses a significant risk to individuals seeking PDF readers, opening document links, or responding to payment-related communications. While its public-facing page displays the title “SecureWorkspace WebPanel,” an internal application route identifies it as “Kaido Panel.” Neither of these names corresponds to a legitimate document viewer or cloud document service.
Beyond the deceptive landing page, researchers discovered protected endpoints for a command-and-control (C2) interface and a live SignalR communication hub. Attempts to access these endpoints without authentication were met with a bearer-authentication challenge, confirming that the site is not merely a static decoy but a fully operational backend designed to provide authorized operators with access to its malicious functions.
Publicly accessible JavaScript code on the site revealed references to a “builder,” “file manager,” an “authentication refresh” function, and a section labeled “loot.” This code further indicated modules dedicated to information theft, banking overlays, PIX payments, and boleto (Brazilian bill payment) lures. This combination of features makes the operation particularly dangerous for Windows users and organizations that handle financial documents.
The observed delivery chain underscores the critical importance of scrutinizing file extensions, not just document names. Historical sandbox records link the Kaido infrastructure to a WebDAV loader that utilizes a .bat dropper and the Windows WebClient service. This method of Windows File Explorer WebDAV abuse allows remote content to be opened in a manner that appears less suspicious than a direct download.
A batch file, when executed, can run arbitrary commands, making it a dangerous format that should never be mistaken for a harmless document. Users must exercise extreme caution with files purporting to be PDFs but possessing unusual extensions, shortcuts, or prompting for downloads. Recent <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/2d8ecc93-0246-4fcc-99de-aeb403a3a520/New-Malware-as-a-service-Leveraging-Adobe-themed-Domain-to-Attack-Windows-Users-Using-.bat-File.pdf?AWSAccessKeyId=ASIA2F3EMEYE4Y7AC2YH&Signature=wsGTBvZeXVvB8hMH2WVyneXV5js%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEBwaCXVzLWVhc3QtMSJFMEMCICHBh%2BJE3JjmHfMEW7mFszyhGiWGcq3PjBSIoOkEE%2FOFAh8WcvHmXo%2FoP2n8YPhrseeBDCPJuiOhV7XdDYbNseyyKvwECOX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NTA1IgxbLenxOYHH3JoH3t4q0ATDsLyPW9P66zXpEJULtx6luFGas3PIron1SvqgnXq77wdeebeMpaariuo
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.