Tactic or Technique: PDF

Attackers use PDF files to deliver malicious content in a format that most people see as safe. These files often appear to be invoices, contracts, or notifications and can include embedded JavaScript, links, or QR codes that lead to phishing sites or malware downloads.
One common example is a fake DocuSign PDF that asks you to scan a QR code or click a link to view a document. The moment you interact, you're taken to a phishing site designed to steal your credentials or deliver malware.
Because PDFs are trusted and can difficult to inspect, they give attackers a way to hide dangerous content behind a familiar format. That trust, combined with limited scanning by some security tools, gives malicious PDFs a clear path into inboxes and environments.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: PDF with recipient email in link
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-recipient-email-in-link-0399d08f
Attachment: Password-protected PDF with fake document indicators
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/attachment-password-protected-pdf-with-fake-document-indicators-b45e4440
Attachment: Invoice and W-9 PDFs with suspicious creators
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/attachment-invoice-and-w-9-pdfs-with-suspicious-creators-305d6e32
Sharepoint link likely unrelated to sender
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/sharepoint-link-likely-unrelated-to-sender-6870f489
Stripe invoice abuse
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/stripe-invoice-abuse-90162d16
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-credential-theft-language-and-link-to-a-free-subdomain-unsolicited-90f4ef4e
Attachment: Legal themed message or PDF with suspicious indicators
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-legal-themed-message-or-pdf-with-suspicious-indicators-19133301
URLhaus: Malicious domain in message body or pdf attachment (trusted reporters)
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/urlhaus-malicious-domain-in-message-body-or-pdf-attachment-trusted-reporters-cfca2986
Attachment: QR code with userinfo portion
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-with-userinfo-portion-9d62cc5c
Brand impersonation: Adobe (QR code)
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-adobe-qr-code-2fc36c6d
Attachment: Archive with pdf, txt and wsf files
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-archive-with-pdf-txt-and-wsf-files-16b2e239
Brand impersonation: Microsoft (QR code)
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-microsoft-qr-code-ed0f772a
Attachment: PDF with suspicious language and redirect to suspicious file type
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-suspicious-language-and-redirect-to-suspicious-file-type-adda3c3f
Attachment: DocuSign impersonation via PDF linking to new domain
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-docusign-impersonation-via-pdf-linking-to-new-domain-f0c96282
Attachment: PDF file with link to fake Bitcoin exchange
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-pdf-file-with-link-to-fake-bitcoin-exchange-47601cb7
Attachment: PDF with link to DMG file download
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-link-to-dmg-file-download-2c486fe0
PDF attachment with Google (AE) redirecting to a php or zip file
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/pdf-attachment-with-google-ae-redirecting-to-a-php-or-zip-file-57ae513f
Attachment: PDF with link to zip containing a wsf file
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-link-to-zip-containing-a-wsf-file-93bc7db4
Attachment: PDF file with low reputation links to suspicious filetypes (unsolicited)
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-pdf-file-with-low-reputation-links-to-suspicious-filetypes-unsolicited-6144f880
Attachment: PDF file with low reputation link to ZIP file (unsolicited)
11d ago
Jan 12th, 2026
Michael Tingle
/feeds/core/detection-rules/attachment-pdf-file-with-low-reputation-link-to-zip-file-unsolicited-d1ee2859