Cyber Security News

Common Tactics Used by Threat Actors to Weaponize PDFs

In the vast and complex world of cybersecurity, danger often hides in the most unsuspecting corners, stalking stealthily where our guard is least prepared.

While the threats, like timeless adversaries, persistently bear and show no signs of disappearing into anonymity.

Cybersecurity analysts at Trustwave SpiderLabs recently observed an uptick in threat actors using PDFs for email-based initial access, highlighting a growing trend in evasive tactics.

PDF enables consistent text and image display across devices, making it ideal for electronic documents like-

  • Resumes
  • Manuals
  • Invoices
  • Forms

Things attract threat actors to PDF

Here below, we have mentioned all the key things that attract the threat actors towards PDF files:-

  • Ubiquity
  • Trustworthiness
  • Difficulty in Detection

Techniques and Methods Used

Here below, we have mentioned all the techniques and methods that threat actors commonly use to weaponize PDF files:-

  • Malicious Hyperlinks: A PDF hyperlink is a clickable element that directs users to external resources. Attackers exploit this by embedding malicious links, often leading to phishing or malware, as seen in Qakbot and IcedID campaigns.
  • Qakbot: Qakbot’s evolving tactics include using PDFs with disguised malicious links to deliver payloads, often posing as legitimate updates to trick users into downloading malware.
Typical infection chain starting with a PDF attachment (Source – Trustwave)
  • Actions and JavaScript: PDFs offer interactivity through actions and JavaScript, but attackers can exploit these for malicious purposes, posing security risks.
  • PDF Dropper: Researchers found a PDF with JavaScript action launching an embedded Office Document, examined using Didier Stevens’ pdfid tool.
  • Vulnerabilities in PDF Reader: Exploiting PDF reader vulnerabilities, like CVE-2021-28550, can grant attackers control over unpatched Adobe Acrobat readers. A decade ago, PDF exploits were widespread, but with the rise of alternative PDF readers and built-in browser support, the threat landscape has shifted, and in-the-wild exploitation has decreased.
  • Social Engineering: Threat actors use social engineering to deceive users into opening PDF files, often in fake brand or service emails, aiming to extract sensitive data. These PDFs appear legitimate but serve malicious purposes.
  • Call-back Phishing: Cybercriminals use PDF invoice emails from generic, undisclosed senders to create urgency and prompt victims to call for subscription updates, deceiving them.
PDF depicts fake purchase information from a well-known brand (Source – Trustwave)

PDFs remain a top choice for threat actors due to their wide use and cross-platform compatibility, presenting an ongoing opportunity for cybercriminals.

Indicators of Compromise

IoC of Qakbot (Source – Trustwave)
IoC of PDF Dropper (Source – Trustwave)
IoC of Callback Phishing (Source – Trustwave)

Keep informed about the latest Cyber Security News by following us on Google NewsLinkedinTwitter, and Facebook.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

7 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago