Cybercriminals have significantly escalated their use of PDF attachments as attack vectors, leveraging the trusted document format to impersonate major brands including Microsoft, DocuSign, Dropbox, PayPal, and Adobe in sophisticated phishing campaigns.
These attacks exploit the widespread trust users place in PDF documents, transforming what should be secure file sharing into a gateway for credential theft and financial fraud.
The malicious campaigns operate through multiple attack vectors, with threat actors embedding entire phishing emails within PDF attachments to evade traditional email security filters.
By encapsulating brand logos, fake invoices, and deceptive content directly into PDF files, attackers bypass textual analysis systems that typically flag suspicious email content.
The portable nature of PDFs makes them ideal vehicles for delivering convincing brand impersonations across various platforms and devices.
These attacks have evolved beyond simple email phishing to incorporate telephone-oriented attack delivery (TOAD), also known as callback phishing, where victims receive PDF attachments containing fake invoices or security alerts with embedded phone numbers.
Cisco Talos analysts identified numerous instances where attackers used Voice over Internet Protocol (VoIP) numbers to maintain anonymity while conducting these social engineering operations.
The geographic scope of these campaigns spans globally, with researchers noting concentrated activity targeting users in the United States during the research period from May 5 to June 5, 2025.
Analysis revealed that Microsoft and DocuSign emerged as the most frequently impersonated brands, while NortonLifeLock, PayPal, and Best Buy’s Geek Squad dominated TOAD-based attacks.
The most sophisticated aspect of these campaigns involves the strategic use of QR codes embedded within PDF attachments, creating a multi-layered deception mechanism.
Attackers position QR codes alongside legitimate-looking brand communications, directing victims to scan codes that redirect to CAPTCHA-protected phishing pages designed to harvest credentials.
Cisco Talos researchers discovered that threat actors exploit PDF annotations to hide malicious URLs while maintaining document legitimacy.
In analyzed samples, attackers embedded multiple URLs within PDF annotations, with one URL (https://eu1.documents.adobe.com/public/) appearing legitimate while a secondary annotation contained the actual phishing destination (https://schopx.com/r?).
This technique allows the visible QR code to link to a trusted site, building victim confidence before the hidden annotation redirects to the malicious endpoint.
The abuse extends to Adobe’s e-signature services, where entire phishing documents are uploaded and distributed through legitimate Adobe infrastructure.
One documented case involved a PayPal impersonation claiming a $699.00 charge for an “Apple iPad Air 11-inch Wi-Fi 256GB-Blue,” complete with transaction ID #08345049MC0STO958308328 and callback number +1 (820)-206-4931.
This demonstrates how attackers layer QR codes with brand impersonation, while the attack sequence illustrates the complete TOAD attack sequence from initial email receipt through victim manipulation and malicious file download.
Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -> Try ANY.RUN now
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…