FBI issues warning — hackers are using fake PDF converters to spread malware and steal your passwords
Here's how to stay safe
Here at Tom’s Guide our expert editors are committed to bringing you the best news, reviews and guides to help you stay informed and ahead of the curve!
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Daily (Mon-Sun)
Tom's Guide Daily
Sign up to get the latest updates on all of your favorite content! From cutting-edge tech news and the hottest streaming buzz to unbeatable deals on the best products and in-depth reviews, we’ve got you covered.
Weekly on Thursday
Tom's AI Guide
Be AI savvy with your weekly newsletter summing up all the biggest AI news you need to know. Plus, analysis from our AI editor and tips on how to use the latest AI tools!
Weekly on Friday
Tom's iGuide
Unlock the vast world of Apple news straight to your inbox. With coverage on everything from exciting product launches to essential software updates, this is your go-to source for the latest updates on all the best Apple content.
Weekly on Monday
Tom's Streaming Guide
Our weekly newsletter is expertly crafted to immerse you in the world of streaming. Stay updated on the latest releases and our top recommendations across your favorite streaming platforms.
Join the club
Get full access to premium articles, exclusive features and a growing list of member rewards.
Be vigilant if you’re using an online PDF converter – the FBI recently issued a warning that threat actors have specifically been using online file conversion services to spread infostealing malware.
As reported by the Indian Express, security firm CloudSEK has discovered an attack that mimics pdfcandy.com in order to trick users into downloading the ArechClient malware, which belongs to the SectopRAT family of infostealers.
The ArechClient malware has been active for several years and is used to steal critical personal data and information like usernames, browser passwords and crypto wallet information.
The report suggests that this latest phishing site, and others like it, have received more than 6,000 visits last month. This indicates that this malware has already been actively exploited by threat actors in order to steal data.
While many people search online for a PDF converter, this site has replicated the visual elements including the logo and the domain name, echoing it by using candyxpdf[.]com and candycoverterpdf[.]com in order to gain legitimacy.
The fake site allows users to upload a PDF file to convert it into a Word document, which requires CAPTCHA verification to complete. Upon completion of the CAPTCHA, users are given a prompt to run a PowerShell command to begin downloading the malware which is downloaded onto their computers under the file name ‘adobe.zip.’
How to stay safe
Because this malware relies on users visiting look-a-like websites instead of the actual company's site that they intent to visit, being extremely cautious and vigilant about what websites you visit to download software is the first step.
Get instant access to breaking news, the hottest reviews, great deals and helpful tips.
Make sure you're downloading software from legitimate sources, and double and triple check the URLs you're visiting and the developer pages.
It also's good to make sure you have one of the best antivirus programs set up, and updated, before you begin downloading files on the internet – many of them include features that can help protect you from malware as well as additional features like a VPN or hardened browser that can help protect you online.
Keep in mind, there are offline tools that will convert these files as well.
More from Tom's Guide
- 1.6 million hit in massive insurance data breach — full names, addresses, SSNs and more exposed
- Hertz confirms data breach that exposed credit cards, drivers' licenses and more — what to do now
- 12 computer security mistakes you're probably making — and what to do instead

Amber Bouman is the senior security editor at Tom's Guide where she writes about antivirus software, home security, identity theft and more. She has long had an interest in personal security, both online and off, and also has an appreciation for martial arts and edged weapons. With over two decades of experience working in tech journalism, Amber has written for a number of publications including PC World, Maximum PC, Tech Hive, and Engadget covering everything from smartphones to smart breast pumps.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.
