Fake “PDF Tool” Ads Push Shift Browser Adware

Heimdal Security · Medium sophistication
Last updated September 3, 2026

Heimdal reports a real-world surge of detections where users were lured by malvertising into downloading executables that pretended to be PDF tools, but installed “Shift Browser” instead. The installer fingerprints the computer (reads system/registry details) before unpacking a Chromium-based payload and making changes associated with persistence and adware behavior. All captured samples were digitally signed by “Shift Technologies Inc,” which helped them appear more trustworthy.

Key findings

  • Heimdal observed “activity on more than 50 client environments in a single day” tied to Shift Browser.
  • The delivery mechanism described is malvertising: ads placed where people search for “manuals, recipes, and document templates.”
  • Captured installer filenames impersonated PDF software (e.g., “shift – pdf_xq6n94.exe”).
  • Dynamic analysis showed fingerprinting/recon behavior (system owner discovery, registry queries, system information discovery) before dropping a packed Chromium component (“chrome.packed.7z”).
  • All samples were code-signed by “Shift Technologies Inc,” which can reduce the chance of SmartScreen or signature-only tools blocking it.
  • Domains/IPs were not listed because “this infrastructure rotates fast enough that a fixed list would be stale within hours.”

Who’s being targeted

  • Commonly targeted roles: All employees, Administrative/Operations, IT support / Helpdesk, Security awareness training audience.
  • Affected industries: Multiple industries (across Heimdal client environments).
  • Attack channels: website.
  • Impersonated: A “PDF tool” download/source (via search ads).

Awareness takeaways

  • Treat “free tool” downloads from ads as high-risk; use approved software sources instead.
  • A valid digital signature does not mean a download is safe, verify behavior and source.
  • Watch for suspicious installer naming patterns that mimic common tools (e.g., PDF utilities).
  • Don’t rely on static blocklists for fast-rotating ad/malvertising infrastructure; focus on behavior and patterns.

Red flags to watch for

  • The downloaded file is an .exe claiming to be a PDF tool
  • Misleading filename pattern like “shift – pdf_*.exe”
  • Download originates from an ad-driven search result rather than a trusted software source
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You Google a free PDF tool, click the top ad, and download a file called “shift – pdf_xgeiup.exe.” You think it’s a PDF helper, but it silently fingerprints your PC, unpacks a Chromium-based Shift Browser, and sets itself up to flood you with ads. Here’s the trap: the installer is digitally signed by “Shift Technologies Inc,” so it looks legit, and the ad comes from wherever you search for manuals, recipes, or document templates. If you ever see a “shift – pdf_*.exe” from a search ad, stop and report it to IT, then only install PDF tools from our approved software portal.

Similar attacks

Fake Recruiters Push “Coding Tests” as RAT Traps

Fake Recruiters Push “Coding Tests” as RAT Traps

Researchers say the Iran-linked group Nimbus Manticore posed as recruiters on LinkedIn and job platforms to send developers “technical challenge” ZIP files that secretly installed cross-platform remote access trojans. The lures used urgency (short test windows) and realistic developer workflows…

September 1, 2026
Fake GTA 6 Demo Sites Push Password Stealer

Fake GTA 6 Demo Sites Push Password Stealer

Attackers are exploiting GTA 6 hype by creating convincing fake Rockstar-branded “demo” websites that appear in Google search results. The sites use “Play Now”/“Official Download” lures to trick people into downloading a small Windows executable that installs Vidar infostealer and steals saved…

August 24, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026
Fake Flash Installer Drops AtlasRAT

Fake Flash Installer Drops AtlasRAT

Researchers reported a real malware campaign where attackers trick people searching for Flash Player into installing a fake “Flash” installer that delivers the AtlasRAT remote-access trojan. Once installed, AtlasRAT gives the attacker long-term remote control, including credential theft and data…

July 31, 2026
Fake Claude App and Alert Apps Drive New Scams

Fake Claude App and Alert Apps Drive New Scams

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to…

July 23, 2026
Odyssey Piracy Traps: Fake Alerts and EXE “Movies”

Odyssey Piracy Traps: Fake Alerts and EXE “Movies”

Researchers reported that scammers set up cloned piracy sites within hours of Christopher Nolan’s The Odyssey release to trick people looking for pirated copies. The scams used a fake “Browser Issue Detected” pop-up to push users into malicious ad redirects and a Windows .exe file disguised as a…

July 20, 2026