Projextor Shows How Malware Can Hide Behind Trusted Electron Executables

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Projextor is a malware campaign that turns ordinary-looking desktop tools into a doorway for hidden code.

Its operators package it inside working document converters, meal planners and recipe applications, so victims receive a program that appears useful from the first click.

The campaign relies on lookalike download sites and installers for free productivity software.

Once a user runs one, the installer retrieves an Electron-based application that can blend its harmful behavior with expected activity such as opening files, saving output and using local system resources.

Analysts at G Data identified a cluster of document converters, food planners and recipe applications that shared the same hidden framework.

G Data said in a report shared with Cyber Security News (CSN) that the apps remained functional while concealing code with far broader access than users would expect.

Projextor Productivity Application Website (Source – G Data)

A convincing tool does not have to be visibly broken to be dangerous: Projextor can add new scripts after installation and includes desktop-capture features that could expose documents, browser sessions, email and collaboration windows.

Since the software performs its advertised task, a user may have little reason to suspect that its unseen components can change later.

That makes visual trust alone a poor test of safety. That risk extends beyond a single device.

Electron is commonly used to make desktop software with web technologies, but it also lets an application reach operating-system functions.

Projextor abuses that trusted structure by installing its main.js and preload.js files in the application resources directory, where they launch automatically when the program starts.

The preload layer normally acts as a controlled bridge between the visible app and more powerful system functions. In the affected samples, main.js deliberately turns off Electron’s context isolation, a safeguard enabled by default in modern versions.

Projextor Infection Chain (Source – G Data)

That choice can give content loaded by the app a path to Node.js capabilities.

Researchers found that the malware can load and execute JavaScript modules from a dedicated injection directory.

This makes the initial download a flexible base rather than a fixed payload, an approach similar to risks covered in Electron framework malware campaigns, where Electron’s access to local resources was used to support data theft.

The lure is effective because the interface behaves normally, reducing obvious warning signs and allowing the installation to seem like routine software use.

The first-stage installers varied, using NSIS, Squirrel Installer or Inno Setup, but all delivered the same second-stage style of application.

One captured sample contained a download address in its NSIS script, showing how a familiar installer format can quietly fetch the more capable component after a victim starts it.

Capture Features Increase Risk

Projextor also implements a custom screen-sharing picker that lists available monitors and application windows, complete with thumbnails.

Screen capture is not malicious by itself, but here it sits alongside arbitrary script execution inside tools advertised for everyday productivity.

If abused, that capability could let an operator watch active work, collect sensitive files displayed on screen and observe sign-in workflows.

Unlike stolen saved passwords, screen capture can reveal information visible only during a live session, including content in browsers, email clients and business applications.

The danger echoes malware targeting screen activity, which shows why data seen during use can be as valuable as stored credentials.

The shared main.js and preload.js design indicates a common campaign or code base, although the researchers said the evidence does not prove the same actor built or operated every application.

The practical lesson is straightforward: download software only from verified sources, confirm the publisher and be wary of sites that closely imitate established services.

Security teams should review newly installed Electron applications, especially unsolicited PDF tools and free utilities, for unexpected preload scripts, insecure settings and calls to external code.

Blocking unapproved software installation and teaching users to avoid search-result download traps can limit exposure, as seen in trojanized productivity tool attacks and fake installer delivery schemes.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-256 A799417BD79060D63E93682F339FBE2868DE3881F9C5865D9B583F5B715C70A9 FlipFormat installer
SHA-256 71656539CC644513396F56100FFB56F9EF9EAA5B7A16B0773D6E5D370A912A88 PDFGrip installer
SHA-256 E7BC36C7345B3894BC1DA3D18FF3DBF0A20713D17B93A585AC0DA65776D29027 FoodFormula installer
SHA-256 3C1DBC3F56E91CC79F0014850E773A7F12BBFEF06680F08F883B2BF12873ECCC KitchenCanvas installer
SHA-256 D50CA2FA212DF1C1FF69B5D26BA594BD39BFD86A71B068A650CC577E5DC9A94E Preload.js script
SHA-256 C21EB14BA63E943DB5EA9AB64AF02A50A17260C7D8538A133C4F6E0957D36F47 Main.js script
SHA-256 4CE5E5768D2F9F71E2835AB8EBC4A2191D436CA3A990A56E9BC264235C7B5B55 Second-stage payload
Domain doceditorinc[.]com Impersonating application-distribution website
URL conv.doceditorinc[.]com/latest/part Second-stage payload download location
Domain meal-formula[.]com Associated distribution website
Domain kitchen-canvas[.]com Associated distribution website
Domain flipformatpdf[.]com Associated distribution website
Domain pdfgrip[.]com Associated distribution website

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world