Tactic or Technique: PDF

Attackers use PDF files to deliver malicious content in a format that most people see as safe. These files often appear to be invoices, contracts, or notifications and can include embedded JavaScript, links, or QR codes that lead to phishing sites or malware downloads.
One common example is a fake DocuSign PDF that asks you to scan a QR code or click a link to view a document. The moment you interact, you're taken to a phishing site designed to steal your credentials or deliver malware.
Because PDFs are trusted and can difficult to inspect, they give attackers a way to hide dangerous content behind a familiar format. That trust, combined with limited scanning by some security tools, gives malicious PDFs a clear path into inboxes and environments.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand Impersonation: Google (QR Code)
3d ago
Aug 4th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
9d ago
Jul 29th, 2026
Sublime Security
Attachment: Fictitious invoice using LinkedIn's address
9d ago
Jul 29th, 2026
Sublime Security
Attachment: Identity Confirmation With Document Unlock Code
10d ago
Jul 28th, 2026
Sublime Security
Brand impersonation: Microsoft (QR code)
11d ago
Jul 27th, 2026
Sublime Security
Attachment: Callback phishing solicitation via pdf file
11d ago
Jul 27th, 2026
Sublime Security
Brand impersonation: Adobe (QR code)
11d ago
Jul 27th, 2026
Sublime Security
Attachment: PDF with secure document acknowledgment prompt
21d ago
Jul 17th, 2026
Sublime Security
Attachment: Single-page PDF with S3-hosted HTML link
22d ago
Jul 16th, 2026
Sublime Security
Stripe invoice abuse
24d ago
Jul 14th, 2026
Sublime Security
Attachment: PDF with suspicious document view lure
24d ago
Jul 14th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft language in EML
25d ago
Jul 13th, 2026
Sublime Security
Attachment: PDF Object Hash associated with a fake invoice and a W-9
1mo ago
Jul 2nd, 2026
Sublime Security
Attachment: PDF with specific W-9 lure
1mo ago
Jul 1st, 2026
Sublime Security
Attachment: Suspicious PDF created with headless browser
1mo ago
Jul 1st, 2026
Sublime Security
Attachment: PDF with quote lure
1mo ago
Jul 1st, 2026
Sublime Security
Attachment: PDF with localhost IP in EXIF title metadata
1mo ago
Jun 29th, 2026
Sublime Security
Attachment: PDF with suspicious internal object reference identifier
1mo ago
Jun 29th, 2026
Sublime Security
Attachment: Invoice and W-9 PDFs with suspicious creators
1mo ago
Jun 26th, 2026
Sublime Security
Attachment: PDF with W-9 form indicators
1mo ago
Jun 26th, 2026
Sublime Security