I PDF file have an interesting function: they can contain attachments (documents or multimedia components), which can be executed with a simple click of the user.
In most cases, these embedded files are harmless, but sometimes they can be used by threat actors to distribute malware.
During the OSINT activity, our Malware Lab intercepted a PDF containing a Microsoft Excel file that, once opened, was capable of executing a malicious payload, stealing various types of data (such as web browser credentials, screenshots, and keystrokes) and exposing the victims of the attack to identity theft, fraud, blackmail, or other cyber attacks.
Since not all types of executable files can be attached to PDFs, the Malware Lab, by conducting practical tests described in the report, verified that some types of files that are on the rise as infection vectors can still be conveyed through PDFs.
If you wish to learn more, here is the link to our full report.
In addition, you can subscribe to the specific mailing list Cyber Studios by Tinexta Defence, to receive updates on upcoming research: https://tinextadefence.it/mailing-list-cyber-studios/