FILEMembers
FILE

Salty Spider Hides Expiro in Adobe's Own Sandbox Temp Path

A campaign attributed to Salty Spider achieves zero detections across 78–91 scanning engines by staging a GZIP payload inside Adobe Acrobat's low-integrity CEF sandbox temp directory. A Romanian ISP node presenting a valid Akamai wildcard TLS certificate handles network traffic, defeating both host-layer and CDN allowlist controls simultaneously.

Jun 25, 2026, 18:28 (UTC+9)Last seenJun 25, 2026Severity52ByCTX TeamActorSalty SpiderKuKuIOC56MITRE29

A 60-kilobyte GZIP archive, first submitted to VirusTotal on 22 March 2025, sits at the centre of an evasion architecture that has so far produced zero detections across 78 scanning engines. The file's distinguishing feature is not its contents — those remain opaque without a sandbox verdict — but where it lives: every observed submission path resolves to C:\Users\user\AppData\Local\Temp\acrocef_low\, the low-integrity process temp directory belonging to Adobe Acrobat's Chromium Embedded…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence