Tactic or Technique: PDF

Attackers use PDF files to deliver malicious content in a format that most people see as safe. These files often appear to be invoices, contracts, or notifications and can include embedded JavaScript, links, or QR codes that lead to phishing sites or malware downloads.
One common example is a fake DocuSign PDF that asks you to scan a QR code or click a link to view a document. The moment you interact, you're taken to a phishing site designed to steal your credentials or deliver malware.
Because PDFs are trusted and can difficult to inspect, they give attackers a way to hide dangerous content behind a familiar format. That trust, combined with limited scanning by some security tools, gives malicious PDFs a clear path into inboxes and environments.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: PDF Link With Valueless Base64 Query Parameter
4h ago
Oct 6th, 2026
Sublime Security
Attachment: PDF teal SharePoint lure
1d ago
Oct 5th, 2026
Sublime Security
Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
2d ago
Oct 4th, 2026
Sublime Security
Attachment: Fictitious invoice using LinkedIn's address
5d ago
Oct 1st, 2026
Sublime Security
Attachment: PDF with specific blurred lure
5d ago
Oct 1st, 2026
Sublime Security
Attachment: PDF Object Hash - Generic MSFT lure
5d ago
Oct 1st, 2026
Sublime Security
Attachment: PDF including a Microsoft lure with specific signature
5d ago
Oct 1st, 2026
Sublime Security
Attachment: PDF credential phishing via wkhtmltopdf/Qt with suspicious link
5d ago
Oct 1st, 2026
Sublime Security
Attachment: QR code with userinfo portion
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Callback phishing solicitation via pdf file
8d ago
Sep 28th, 2026
Sublime Security
Attachment: PDF W9 signature reuse
8d ago
Sep 28th, 2026
Sublime Security
Brand Impersonation: Google (QR Code)
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
11d ago
Sep 25th, 2026
Sublime Security
Brand impersonation: Adobe (QR code)
13d ago
Sep 23rd, 2026
Sublime Security
Credential phishing: Tax form impersonation with payment request
13d ago
Sep 23rd, 2026
Sublime Security
Sharepoint link likely unrelated to sender
13d ago
Sep 23rd, 2026
Sublime Security
Attachment: PDF with Microsoft Purview message impersonation
13d ago
Sep 23rd, 2026
Sublime Security
Attachment: Compensation review lure with QR code
13d ago
Sep 23rd, 2026
Sublime Security
Brand impersonation: SharePoint PDF attachment with credential theft language
13d ago
Sep 23rd, 2026
Sublime Security
Suspicious attachment with unscannable Cloudflare link
13d ago
Sep 23rd, 2026
Sublime Security