Tactic or Technique: PDF

Attackers use PDF files to deliver malicious content in a format that most people see as safe. These files often appear to be invoices, contracts, or notifications and can include embedded JavaScript, links, or QR codes that lead to phishing sites or malware downloads.
One common example is a fake DocuSign PDF that asks you to scan a QR code or click a link to view a document. The moment you interact, you're taken to a phishing site designed to steal your credentials or deliver malware.
Because PDFs are trusted and can difficult to inspect, they give attackers a way to hide dangerous content behind a familiar format. That trust, combined with limited scanning by some security tools, gives malicious PDFs a clear path into inboxes and environments.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: PDF Grant Payment lure with embedded link
21h ago
Aug 26th, 2026
Sublime Security
Attachment: Risk assessment PDF with inline image
2d ago
Aug 25th, 2026
Sublime Security
Attachment: Invoice and W-9 PDFs with suspicious creators
2d ago
Aug 25th, 2026
Sublime Security
Attachment: PDF proposal with credential theft indicators
3d ago
Aug 24th, 2026
Sublime Security
Attachment: PDF with suspicious HeadlessChrome metadata
3d ago
Aug 24th, 2026
Sublime Security
Attachment: QuickBooks PDF lure
7d ago
Aug 20th, 2026
Sublime Security
Attachment: PDF with embedded box-lure and javascript
8d ago
Aug 19th, 2026
Sublime Security
Attachment: PDF templated investment lure
8d ago
Aug 19th, 2026
Sublime Security
Attachment: PDF with a suspicious string and single URL
8d ago
Aug 19th, 2026
Sublime Security
Attachment: PDF with suspicious link and action-oriented language
9d ago
Aug 18th, 2026
Sublime Security
Attachment: PDF with base64 JavaScript and eval functions
16d ago
Aug 11th, 2026
Sublime Security
Brand Impersonation: Google (QR Code)
23d ago
Aug 4th, 2026
Sublime Security
Attachment: Fictitious invoice using LinkedIn's address
29d ago
Jul 29th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
29d ago
Jul 29th, 2026
Sublime Security
Attachment: Identity Confirmation With Document Unlock Code
1mo ago
Jul 28th, 2026
Sublime Security
Brand impersonation: Microsoft (QR code)
1mo ago
Jul 27th, 2026
Sublime Security
Brand impersonation: Adobe (QR code)
1mo ago
Jul 27th, 2026
Sublime Security
Attachment: Callback phishing solicitation via pdf file
1mo ago
Jul 27th, 2026
Sublime Security
Attachment: PDF with secure document acknowledgment prompt
1mo ago
Jul 17th, 2026
Sublime Security
Attachment: Single-page PDF with S3-hosted HTML link
1mo ago
Jul 16th, 2026
Sublime Security