Adobe Reader Zero-Day Actively Exploited via Malicious PDFs Targeting Russian Oil & Gas Sector
Adobe Reader Zero-Day Actively Exploited via Malicious PDFs (TL-2026-0350), also tracked as yummy_adobe_exploit_uwu campaign, is a critical-severity zero-day vulnerability scored CVSS 9, first published 2026-04-10. It has no confirmed attribution, affects Adobe Acrobat Reader, maps to 12 MITRE ATT&CK techniques (T1027, T1036.005, T1041), and is covered by 9 detection rules and 14 indicators of compromise.
Key facts for TL-2026-0350
- Threat ID
- TL-2026-0350
- Also known as
- yummy_adobe_exploit_uwu campaign, Adobe Synchronizer Callhome
- Severity
- CRITICAL
- CVSS
- 9 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- ZERO_DAY
- First published
- 2026-04-10
- Last reviewed
- 2026-04-10
- Attribution confidence
- NONE
- Motivation
- ESPIONAGE
- Target sectors
- energy, oil-and-gas, critical-infrastructure
- Target regions
- Russia, Commonwealth of Independent States
- Detection rules
- 9
- Indicators of compromise
- 14
Malware and tooling in Adobe Reader Zero-Day Actively Exploited via Malicious PDFs
Malware and tooling: Malware/Callhome, Troj/PDF-BG, Custom HTTP stager over non-standard ports
An unpatched Adobe Reader zero-day is being actively exploited via weaponized PDFs containing obfuscated JavaScript that abuses privileged Acrobat APIs for code execution and data exfiltration. Sophos disclosed the campaign on 2026-04-07 with telemetry dating back to December 2025. Russian-language lures indicate targeted operations against the Russian oil and gas sector.
How Adobe Reader Zero-Day Actively Exploited via Malicious PDFs works
Sophos X-Ops publicly disclosed on April 7, 2026 an active in-the-wild exploitation campaign leveraging a previously unknown vulnerability in Adobe Reader. The attack chain begins with social-engineering delivery of weaponized PDF documents carrying Russian-language lures themed around invoices and procurement documents associated with the Russian oil & gas sector. When opened in a vulnerable Adobe Reader build, the PDF executes heavily obfuscated JavaScript that invokes privileged Acrobat API methods normally restricted by the reader''s JavaScript sandbox. The privileged API abuse allows the attacker to drop and execute additional payloads, read local files, and initiate outbound command-and-control callbacks.
Sophos telemetry dates the earliest observed exploitation to December 2025, giving the campaign a four-month operational window before public disclosure and before Adobe shipped a patch. Analyzed samples include yummy_adobe_exploit_uwu.pdf (MD5 1929da3ef904efb8c940679045452321, SHA256 65dca34b04416f9a113f09718cbe51e11fd58e7287b7863e37f393ed4d25dde7) and Invoice540.pdf (MD5 522cda0c18b410daa033dc66c48eb75a). The embedded JavaScript layer stages decoded shellcode in memory, then calls out to hard-coded command-and-control endpoints. Observed C2 infrastructure includes the domain ado-read-parser[.]com and two raw-IP callback listeners on 169.40.2.68:45191 and 188.214.34.20:34123, with the stager identifying itself via the User-Agent string ''Adobe Synchronizer'' to masquerade as legitimate Adobe update traffic.
Sophos ships protection for the samples under Troj/PDF-BG and the network activity under Malware/Callhome, confirming real victims in production telemetry. As of disclosure there is no CVE assignment and no vendor patch — defenders should treat every inbound PDF with executable JavaScript as suspicious, disable Acrobat JavaScript where feasible, and block the published IOCs at the perimeter. The narrow victimology (Russian energy sector) and the sustained four-month operational window point to a capable, state-aligned or state-adjacent intrusion set rather than commodity crimeware.
MITRE ATT&CK techniques used in TL-2026-0350
defense-evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1059.007 JavaScript; T1203 Exploitation for Client Execution; T1204.002 Malicious File
command-and-control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1571 Non-Standard Port
discovery
T1082 System Information Discovery
initial-access
Affected products and versions in Adobe Reader Zero-Day Actively Exploited via Malicious PDFs
- Adobe — Acrobat Reader
Vulnerable versions: unspecified — all current builds as of 2026-04-09 - Adobe — Acrobat
Vulnerable versions: unspecified — all current builds as of 2026-04-09
Remediation for Adobe Reader Zero-Day Actively Exploited via Malicious PDFs
Patches
- No patch available as of 2026-04-09. Monitor Adobe Product Security Incident Response Team (PSIRT) advisories for the forthcoming out-of-band update.
Immediate actions
- Block ado-read-parser[.]com at DNS/proxy layer
- Block outbound traffic to 169.40.2.68 and 188.214.34.20
- Disable JavaScript execution in Adobe Reader/Acrobat (Edit > Preferences > JavaScript > uncheck Enable Acrobat JavaScript)
- Quarantine any PDF matching the published hashes at the mail gateway
- Alert on User-Agent string ''Adobe Synchronizer'' in egress proxy logs
Workarounds
- Disable Acrobat JavaScript via Group Policy HKCU\Software\Adobe\Acrobat Reader\<ver>\JSPrefs\bEnableJS=0
- Use Protected View / Protected Mode for all files originating from the internet
- Replace Adobe Reader with alternative PDF viewers on high-risk endpoints until patched
Longer-term hardening
- Deploy application-aware EDR capable of detecting Acrobat.exe spawning child processes or making anomalous outbound connections
- Route all PDF attachments through a detonation sandbox before delivery
- Enforce attack-surface-reduction rules blocking Office and Adobe child-process creation
- Maintain behavioral detections for privileged Acrobat JS API invocation patterns
Weaknesses (CWE) in Adobe Reader Zero-Day Actively Exploited via Malicious PDFs
CWE-94, CWE-693, CWE-829
Timeline of Adobe Reader Zero-Day Actively Exploited via Malicious PDFs
- Earliest Sophos telemetry of malicious PDF samples abusing the Adobe Reader zero-day in the wild, targeting Russian-language victims.
- Additional weaponized PDF samples (Invoice540.pdf) observed in sustained targeting of oil and gas sector recipients.
- Command-and-control callbacks to ado-read-parser[.]com and IP listeners on 169.40.2.68:45191 and 188.214.34.20:34123 confirmed active.
- Sophos X-Ops completes internal triage and coordinates responsible disclosure with Adobe PSIRT.
- Sophos publishes public blog disclosing the Adobe Reader zero-day in active exploitation, releasing sample hashes and C2 IOCs.
- No CVE assigned and no Adobe patch available. Defenders advised to disable Acrobat JavaScript and block published IOCs at egress.
- As of 2026-05-29, this Adobe Reader zero-day was assigned CVE-2026-34621 (prototype pollution, CVSS 8.6) and patched by Adobe in an emergency out-of-band update (Acrobat/Reader DC 26.001.21411) on ~Apr 11-13, 2026. CISA added it to KEV on Apr 13 (FCEB deadline Apr 27); the zero-day window is closed, though unpatched endpoints remain at risk.
Sources cited for Adobe Reader Zero-Day Actively Exploited via Malicious PDFs
Threats related to Adobe Reader Zero-Day Actively Exploited via Malicious PDFs
Detection coverage for TL-2026-0350
As of 2026-04-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0350 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.