Cyber Security News

Threat Actors Weaponize PDFs to Impersonate Microsoft, DocuSign, Dropbox and More in Phishing Attack

Cybercriminals have significantly escalated their use of PDF attachments as attack vectors, leveraging the trusted document format to impersonate major brands including Microsoft, DocuSign, Dropbox, PayPal, and Adobe in sophisticated phishing campaigns.

These attacks exploit the widespread trust users place in PDF documents, transforming what should be secure file sharing into a gateway for credential theft and financial fraud.

The malicious campaigns operate through multiple attack vectors, with threat actors embedding entire phishing emails within PDF attachments to evade traditional email security filters.

By encapsulating brand logos, fake invoices, and deceptive content directly into PDF files, attackers bypass textual analysis systems that typically flag suspicious email content.

The portable nature of PDFs makes them ideal vehicles for delivering convincing brand impersonations across various platforms and devices.

These attacks have evolved beyond simple email phishing to incorporate telephone-oriented attack delivery (TOAD), also known as callback phishing, where victims receive PDF attachments containing fake invoices or security alerts with embedded phone numbers.

Cisco Talos analysts identified numerous instances where attackers used Voice over Internet Protocol (VoIP) numbers to maintain anonymity while conducting these social engineering operations.

The geographic scope of these campaigns spans globally, with researchers noting concentrated activity targeting users in the United States during the research period from May 5 to June 5, 2025.

Analysis revealed that Microsoft and DocuSign emerged as the most frequently impersonated brands, while NortonLifeLock, PayPal, and Best Buy’s Geek Squad dominated TOAD-based attacks.

QR Code Integration and PDF Annotation Exploitation

The most sophisticated aspect of these campaigns involves the strategic use of QR codes embedded within PDF attachments, creating a multi-layered deception mechanism.

A QR code phishing email impersonating the Microsoft brand (Source – Cisco Talos)

Attackers position QR codes alongside legitimate-looking brand communications, directing victims to scan codes that redirect to CAPTCHA-protected phishing pages designed to harvest credentials.

Cisco Talos researchers discovered that threat actors exploit PDF annotations to hide malicious URLs while maintaining document legitimacy.

In analyzed samples, attackers embedded multiple URLs within PDF annotations, with one URL (https://eu1.documents.adobe.com/public/) appearing legitimate while a secondary annotation contained the actual phishing destination (https://schopx.com/r?).

This technique allows the visible QR code to link to a trusted site, building victim confidence before the hidden annotation redirects to the malicious endpoint.

The abuse extends to Adobe’s e-signature services, where entire phishing documents are uploaded and distributed through legitimate Adobe infrastructure.

One documented case involved a PayPal impersonation claiming a $699.00 charge for an “Apple iPad Air 11-inch Wi-Fi 256GB-Blue,” complete with transaction ID #08345049MC0STO958308328 and callback number +1 (820)-206-4931.

TOAD attack sequence (Source – Cisco Talos)

This demonstrates how attackers layer QR codes with brand impersonation, while the attack sequence illustrates the complete TOAD attack sequence from initial email receipt through victim manipulation and malicious file download.

Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -> Try ANY.RUN now

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago