Tactic or Technique: PDF

Attackers use PDF files to deliver malicious content in a format that most people see as safe. These files often appear to be invoices, contracts, or notifications and can include embedded JavaScript, links, or QR codes that lead to phishing sites or malware downloads.
One common example is a fake DocuSign PDF that asks you to scan a QR code or click a link to view a document. The moment you interact, you're taken to a phishing site designed to steal your credentials or deliver malware.
Because PDFs are trusted and can difficult to inspect, they give attackers a way to hide dangerous content behind a familiar format. That trust, combined with limited scanning by some security tools, gives malicious PDFs a clear path into inboxes and environments.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
12h ago
Jun 1st, 2026
Sublime Security
Brand impersonation: Adobe Acrobat Sign PDF phishing file format template
14h ago
Jun 1st, 2026
Sublime Security
Attachment: PDF with specific author metadata
20h ago
Jun 1st, 2026
Sublime Security
Attachment: PDF with suspicious link and action-oriented language
15d ago
May 18th, 2026
Sublime Security
Attachment: Microsoft impersonation via PDF with link and suspicious language
19d ago
May 14th, 2026
Sublime Security
Attachment: PDF with a suspicious string and single URL
20d ago
May 13th, 2026
Sublime Security
Attachment: Suspicious PDF created with headless browser
26d ago
May 7th, 2026
Sublime Security
Brand impersonation: SharePoint PDF attachment with credential theft language
29d ago
May 4th, 2026
Sublime Security
Attachment: PDF with suspicious HeadlessChrome metadata
1mo ago
May 1st, 2026
Sublime Security
Attachment: QR code with userinfo portion
1mo ago
Apr 30th, 2026
Sublime Security
Attachment: Fake voicemail via PDF
1mo ago
Apr 30th, 2026
Sublime Security
Attachment: Decoy PDF author (Julie P.)
1mo ago
Apr 29th, 2026
Sublime Security
Adobe branded PDF file linking to a password-protected file from untrusted sender
1mo ago
Apr 29th, 2026
Sublime Security
Attachment: QR code link with base64-encoded recipient address
1mo ago
Apr 29th, 2026
Sublime Security
Attachment: PDF with suspicious view document characteristics
1mo ago
Apr 23rd, 2026
Sublime Security
Attachment: PDF with JSFck obfuscation
1mo ago
Apr 22nd, 2026
Sublime Security
Attachment: PDF with CVE-2026-34621 lures
1mo ago
Apr 22nd, 2026
Sublime Security
Brand impersonation: Adobe (QR code)
1mo ago
Apr 20th, 2026
Sublime Security
Attachment: PDF with split QR code
1mo ago
Apr 15th, 2026
Sublime Security
Attachment: PDF With SAI Global ISO9001 Logo
1mo ago
Apr 15th, 2026
Sublime Security