Tactic or Technique: PDF

Attackers use PDF files to deliver malicious content in a format that most people see as safe. These files often appear to be invoices, contracts, or notifications and can include embedded JavaScript, links, or QR codes that lead to phishing sites or malware downloads.
One common example is a fake DocuSign PDF that asks you to scan a QR code or click a link to view a document. The moment you interact, you're taken to a phishing site designed to steal your credentials or deliver malware.
Because PDFs are trusted and can difficult to inspect, they give attackers a way to hide dangerous content behind a familiar format. That trust, combined with limited scanning by some security tools, gives malicious PDFs a clear path into inboxes and environments.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: PDF bid/proposal lure with credential theft indicators
3d ago
Mar 27th, 2026
Sublime Security
Attachment: PDF contains W9 or invoice YARA signatures
12d ago
Mar 18th, 2026
Sublime Security
Link: PDF display text with fake copyright claim template
12d ago
Mar 18th, 2026
Sublime Security
Attachment: PDF proposal with credential theft indicators
13d ago
Mar 17th, 2026
Sublime Security
Attachment: PDF with a suspicious string and single URL
13d ago
Mar 17th, 2026
Sublime Security
Attachment: PDF with suspicious link and action-oriented language
24d ago
Mar 6th, 2026
Sublime Security
Attachment: PDF with recipient email in link
27d ago
Mar 3rd, 2026
Sublime Security
Attachment: Finance themed PDF with observed phishing template
28d ago
Mar 2nd, 2026
Sublime Security
Attachment: PDF Object Hash - Encrypted PDFs with fake payment notification
28d ago
Mar 2nd, 2026
Sublime Security
Link: SharePoint OneNote or PDF link with self sender behavior
1mo ago
Feb 27th, 2026
Sublime Security
Attachment: PDF with multistage landing - ClickUp abuse
1mo ago
Feb 27th, 2026
Sublime Security
Attachment: PDF with ReportLab library and default metadata
1mo ago
Feb 27th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
1mo ago
Feb 26th, 2026
Sublime Security
Attachment: PDF with password in filename matching body text
1mo ago
Feb 19th, 2026
Sublime Security
Credential phishing: Tax form impersonation with payment request
1mo ago
Feb 13th, 2026
Sublime Security
Attachment: Self-sender PDF with minimal content and view prompt
1mo ago
Feb 12th, 2026
Sublime Security
Link: PDF filename impersonation with credential theft language
1mo ago
Feb 12th, 2026
Sublime Security
Attachment: Legal themed message or PDF with suspicious indicators
1mo ago
Feb 5th, 2026
Sublime Security
Attachment: Password-protected PDF with fake document indicators
2mo ago
Jan 21st, 2026
Sublime Security
Attachment: Invoice and W-9 PDFs with suspicious creators
2mo ago
Jan 21st, 2026
Sublime Security