
Salty Spider Hides Expiro in Adobe's Own Sandbox Temp Path
A campaign attributed to Salty Spider achieves zero detections across 78–91 scanning engines by staging a GZIP payload inside Adobe Acrobat's low-integrity CEF sandbox temp directory. A Romanian ISP node presenting a valid Akamai wildcard TLS certificate handles network traffic, defeating both host-layer and CDN allowlist controls simultaneously.
A 60-kilobyte GZIP archive, first submitted to VirusTotal on 22 March 2025, sits at the centre of an evasion architecture that has so far produced zero detections across 78 scanning engines. The file's distinguishing feature is not its contents — those remain opaque without a sandbox verdict — but where it lives: every observed submission path resolves to C:\Users\user\AppData\Local\Temp\acrocef_low\, the low-integrity process temp directory belonging to Adobe Acrobat's Chromium Embedded…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read