"I'm so impressed with what they've done here," security expert Troy Hunt tweeted.
The spyware steals victims' photos, contacts, call logs and can also spy on conversations when the infected device is within range.
Votiro's findings come as hackers continue to develop new, clever ways to exploit victims and earn cryptocurrency often by exploiting popular platforms.
The seemingly secure document, however, actually contains the Adwind malware that is capable of exfiltrating data from the infected computer.
BitFunder founder Jon Montroll repeatedly lied to the Securities Exchange Commission to cover up a hack that saw the theft of over 6,000 bitcoins.
Despite being available for download for years, none of the antivirus engines are able to detect it as malicious.
The incident comes as cryptojacking heists become increasingly common and sophisticated alongside the rise and popularity of cryptocurrency.
"We believe this is the next team to watch," FireEye's director of intelligence analysis John Hultquist said.
Authorities said thousands have already fallen victim to the scheme described as a "new twist on an old scam".
The finding immediately triggered fierce uproar with many saying "there is absolutely no justification" for including a password stealer in a flight simulation add-on.
Hackers have been found targeting several vulnerabilities in different servers to secretly install cryptomining software and generate digital currencies using victims' resources.
Hackers have targeted a slew of banks worldwide in recent years to gain illegal access to the Swift network and initiate fraudulent money transfers.
"We take the security of personally identifiable information very seriously," California's Department of Fish and Wildlife said.
For their roles in what US prosecutors have called "one of the largest" known cybercrime schemes, two Russian nationals were handed lengthy prison terms this week.
More than 110,000 scanned ID documents including passports and driving licences linked to a subsidiary of delivery firm FedEx was left exposed online, experts reveal.
GPU manufacturers are scrambling to deal with rapidly rising demand for graphics cards.
The new variant of AndroRAT disguises itself as an app called TrashCleaner, which once installed, can allow hackers to perform various malicious activities.
"Salon never has access to your personal files or information during this process," the media site notes.
Widely believed to be linked to the North Korean regime, Lazarus Group has been linked to the 2014 Sony hack and the WannaCry ransomware attack in 2017 among others.
The hacker group created customised chat apps with backdoor functionalities for both Android and Windows.
Over the past few months, security experts have observed a steady rise in cryptojacking attacks, malware-based miners and browser-based cryptominers.
Over the past few months, researchers observed an uptick in phishing campaigns targeting several Olympics organisations by the Kremlin-linked hacking group Fancy Bear.