Tactic or Technique: PDF

Attackers use PDF files to deliver malicious content in a format that most people see as safe. These files often appear to be invoices, contracts, or notifications and can include embedded JavaScript, links, or QR codes that lead to phishing sites or malware downloads.
One common example is a fake DocuSign PDF that asks you to scan a QR code or click a link to view a document. The moment you interact, you're taken to a phishing site designed to steal your credentials or deliver malware.
Because PDFs are trusted and can difficult to inspect, they give attackers a way to hide dangerous content behind a familiar format. That trust, combined with limited scanning by some security tools, gives malicious PDFs a clear path into inboxes and environments.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: PDF with Microsoft Purview message impersonation
2d ago
Nov 10th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-microsoft-purview-message-impersonation-571d4964
Attachment: Encrypted PDF with credential theft body
4d ago
Nov 8th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-encrypted-pdf-with-credential-theft-body-c9596c9a
Brand impersonation: SharePoint PDF attachment with credential theft language
5d ago
Nov 7th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sharepoint-pdf-attachment-with-credential-theft-language-ae3756fa
Attachment: Suspicious employee policy update document lure
14d ago
Oct 29th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-suspicious-employee-policy-update-document-lure-a8bf1fd1
Attachment: Compensation review lure with QR code
14d ago
Oct 29th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-compensation-review-lure-with-qr-code-9fd8185c
Brand impersonation: DocuSign PDF attachment with suspicious link
21d ago
Oct 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-pdf-attachment-with-suspicious-link-2601cbb7
Brand Impersonation: Google (QR Code)
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-google-qr-code-7ffd184c
Brand impersonation: DocuSign (QR code)
28d ago
Oct 15th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-qr-code-0b16c28a
Attachment: PDF with recipient email in link
1mo ago
Oct 10th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-recipient-email-in-link-0399d08f
Brand impersonation: Adobe (QR code)
1mo ago
Oct 3rd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-adobe-qr-code-2fc36c6d
Brand impersonation: Microsoft (QR code)
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-microsoft-qr-code-ed0f772a
Attachment: Fake scan-to-email
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/attachment-fake-scan-to-email-ea850cc1
Sharepoint link likely unrelated to sender
1mo ago
Sep 19th, 2025
Sublime Security
/feeds/core/detection-rules/sharepoint-link-likely-unrelated-to-sender-6870f489
Attachment: Suspicious PDF created with headless browser
1mo ago
Sep 17th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-suspicious-pdf-created-with-headless-browser-8f3108d7
Credential phishing: Tax form impersonation with payment request
2mo ago
Sep 10th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-tax-form-impersonation-with-payment-request-717695cf
Attachment: Fictitious invoice using LinkedIn's address
2mo ago
Sep 3rd, 2025
Sublime Security
/feeds/core/detection-rules/attachment-fictitious-invoice-using-linkedins-address-aeee3d9f
Attachment: QR code link with base64-encoded recipient address
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-link-with-base64-encoded-recipient-address-927a0c1a
Attachment: DocuSign impersonation via PDF linking to new domain
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-docusign-impersonation-via-pdf-linking-to-new-domain-f0c96282
Attachment: Decoy PDF author (Julie P.)
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-decoy-pdf-author-julie-p-4324213a
Suspicious attachment: Duplicate decoy PDF files
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/suspicious-attachment-duplicate-decoy-pdf-files-79b9b2e7