Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Vulnerabilities in Harman Kardon Infotainment Systems Expose Android Car Screens
August 24, 2026
Anthropic Claude AI Experiences Widespread Outage and Elevated Errors
August 24, 2026
Hugging Face Reportedly Explores $13 Billion Sale After AI Security Incident
August 24, 2026
Home/CyberSecurity News/New MaaS Targets Windows Users with Adobe-Themed .bat Files
CyberSecurity News

New MaaS Targets Windows Users with Adobe-Themed .bat Files

Key Takeaways A new Malware-as-a-Service (MaaS) platform, dubbed “Kaido Panel,” is actively targeting Windows users. The operation leverages an Adobe-themed domain,...

David kimber
David kimber
August 24, 2026 3 Min Read
4 0

Key Takeaways

  • A new Malware-as-a-Service (MaaS) platform, dubbed “Kaido Panel,” is actively targeting Windows users.
  • The operation leverages an Adobe-themed domain, acrobatreaderonline.com, to trick victims into downloading malicious files.
  • The MaaS platform offers features for data exfiltration, banking overlays, and payment fraud, lowering the barrier for cybercriminals.
  • Initial infection often occurs via malicious .bat files delivered through WebDAV remote folders, exploiting the Windows WebClient service.
  • Organizations and individual users are urged to block associated domains and monitor for suspicious WebClient activity.

A sophisticated criminal enterprise is operating a malicious service disguised as an Adobe Acrobat Reader download site. The domain, acrobatreaderonline.com, is not a legitimate document service but rather a malicious platform designed to facilitate attacks against Windows users. This Malware-as-a-Service (MaaS) operation capitalizes on the common tactic of using trusted-looking themes, such as document or payment lures, to trick unsuspecting victims into downloading harmful software.

Previous activity linked to the same malicious infrastructure involved the delivery of Windows batch (.bat) files through WebDAV remote folders. In these instances, what appeared to be a PDF or payment document (boleto) would serve as a deceptive entry point for malware. This method effectively transforms seemingly innocuous files into vectors for system compromise.

Security researchers at Clandestine uncovered this operation during an open-source investigation on August 23, 2026. They identified a fully functional MaaS control panel hosted on the Adobe-themed domain. Clandestine said in a report shared with Cyber Security News (CSN) that the website is not an authentic Adobe Reader portal and should be considered unsafe. The discovery highlights how a convincing brand impersonation can seamlessly transition from a phishing bait to a fully operational criminal platform, offering features like victim data collection, file management, and malware module deployment, thereby lowering the barrier for potential attackers.

https://t.co/LaGothWxgV is not Adobe Acrobat Reader Online.
Open-source review on 23 August 2026 shows a live malware-as-a-service panel behind an Adobe-themed domain. The page title is SecureWorkspace WebPanel; /api/ renders as Kaido Panel. The stack is Vite/React, Tailwind… pic.twitter.com/arJGRFqXto

New Malware-as-a-service Leveraging Adobe-themed Domain

The deceptive domain poses a significant risk to individuals seeking PDF readers, opening document links, or responding to payment-related communications. While its public-facing page displays the title “SecureWorkspace WebPanel,” an internal application route identifies it as “Kaido Panel.” Neither of these names corresponds to a legitimate document viewer or cloud document service.

Beyond the deceptive landing page, researchers discovered protected endpoints for a command-and-control (C2) interface and a live SignalR communication hub. Attempts to access these endpoints without authentication were met with a bearer-authentication challenge, confirming that the site is not merely a static decoy but a fully operational backend designed to provide authorized operators with access to its malicious functions.

Publicly accessible JavaScript code on the site revealed references to a “builder,” “file manager,” an “authentication refresh” function, and a section labeled “loot.” This code further indicated modules dedicated to information theft, banking overlays, PIX payments, and boleto (Brazilian bill payment) lures. This combination of features makes the operation particularly dangerous for Windows users and organizations that handle financial documents.

The observed delivery chain underscores the critical importance of scrutinizing file extensions, not just document names. Historical sandbox records link the Kaido infrastructure to a WebDAV loader that utilizes a .bat dropper and the Windows WebClient service. This method of Windows File Explorer WebDAV abuse allows remote content to be opened in a manner that appears less suspicious than a direct download.

A batch file, when executed, can run arbitrary commands, making it a dangerous format that should never be mistaken for a harmless document. Users must exercise extreme caution with files purporting to be PDFs but possessing unusual extensions, shortcuts, or prompting for downloads. Recent <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/2d8ecc93-0246-4fcc-99de-aeb403a3a520/New-Malware-as-a-service-Leveraging-Adobe-themed-Domain-to-Attack-Windows-Users-Using-.bat-File.pdf?AWSAccessKeyId=ASIA2F3EMEYE4Y7AC2YH&Signature=wsGTBvZeXVvB8hMH2WVyneXV5js%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEBwaCXVzLWVhc3QtMSJFMEMCICHBh%2BJE3JjmHfMEW7mFszyhGiWGcq3PjBSIoOkEE%2FOFAh8WcvHmXo%2FoP2n8YPhrseeBDCPJuiOhV7XdDYbNseyyKvwECOX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NTA1IgxbLenxOYHH3JoH3t4q0ATDsLyPW9P66zXpEJULtx6luFGas3PIron1SvqgnXq77wdeebeMpaariuo

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Cybermes AI Red Teaming Agent Automates Penetration Testing

Next Post

New npm Malware RedC2 Steals Credentials, Pivots Networks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
New MaaS Targets Windows Users with Adobe-Themed .bat Files
August 24, 2026
Cybermes AI Red Teaming Agent Automates Penetration Testing
August 24, 2026
Critical isolated-vm Flaw Lets JavaScript Escape Sandbox, Hijack Host
August 24, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us