Malicious PDFs: how to recognize them and protect yourself from attacks

PDFs are simple, widely used files that, in principle, do not raise suspicion. They work on almost any operating system and there is a large amount of free software and websites where you can read and modify them. ESET, a leading company in proactive threat detection, warns that this popularity is one of the reasons why cybercriminals use them as a great tool for deception, and that is why it is essential to be vigilant, verify the origin of the files and adopt good security practices.

A malicious PDF can install or download malware, steal private or sensitive information, or even exploit system or PDF reader vulnerabilities. According to ESET, they are generally distributed as attachments in phishing emails that appeal to urgency, emotion, or concern to induce their opening. According to the latest ESET Threat Report, PDF files are in sixth place in the TOP 10 threat detections, and are one of the trends in attacks through malicious emails.

"Attackers strive to avoid being detected by users and simulate legitimate PDFs. It's easy for them to contain malicious elements that are imperceptible at first glance, especially for users outside of cybersecurity or computer science," comments Fabiana Ramirez Cuenca, Cybersecurity Researcher at ESET Latin America.

Among the most common examples of the different ways they seek to disguise malicious PDFs are:
Purchase or debt invoices, with names like "Invoice.pdf"
Job resumes, mainly in attacks targeting companies
Results of medical studies
Documents linked to financial, banking or governmental entities

One of the most common methods used by attackers is to embed scripts -code snippets- that can be designed to download malware, open remote connections, or execute commands and processes in the background, among other malicious actions. They can also contain hidden links that open when interacting with certain functionalities of the file. In addition, they can exploit some vulnerability or failure of popular readers, such as Adobe Reader, Foxit, among others.

A phishing campaign documented by ESET used PDF files to distribute the Grandoreiro banking trojan. The attack began with a malicious link that led to the download of the infected PDF.

In the spotlight

  • aplicacion - banner 300px

  • banner altices 300x250 junio 2025

Explore more

Former John Galliano lawyer condemned on appeal for having swindled the stylist

The Paris Court of Appeal confirmed this Tuesday the two-year suspended prison sentence handed down in the first instance in June 2023 against the former lawyer of the stylist John Galliano, who had sued him in 2011 for fraud. Stéphane Zerbib, who claims his innocence, was found guilty of having diverted 856,500 euros between 2008 […]

UTESUR Law Students Hold Mock Hearing

Azua. – Law students from the Universidad Tecnológica del Sur (UTESUR) held a mock hearing to conclude the semester in the Criminal Procedure Law course, taught by Professor Francisco Nova. The practice was developed as a coercive measure hearing, in which the students assumed the different roles of the criminal process, demonstrating skills in oral […]

The "Christmas Breeze" from Inespre arrives in Azua with food at fair prices

Azua. – With the presence of the provincial governor, licensed Maria Minerva Navarro, and the executive director of the Price Stabilization Institute (Inespre), engineer David Herrera Díaz, the special "La Brisita Navideña" day was inaugurated in the province of Azua. The initiative takes place on Tuesdays the 16th and Wednesdays the 17th of December at […]

In 2025, it became difficult for Dominicans to pay their debts.

The year 2025 was difficult for Dominicans to meet on time the credit commitments they have acquired in the different Financial Intermediation Entities (Banks). Both the average delinquency rate of the entire financial system and the total amount of past-due loans have been increasing from January 2025 to October 2025, and are at levels similar […]

Energy and Mines reaches 100% in governmental transparency

The Ministry of Energy and Mines (MEM) once again achieved the maximum score of 100% in the Standardized Transparency Index corresponding to October 2025, according to a recent report from the Transparency and Open Government Directorate of the General Directorate of Ethics and Governmental Integrity (Digeig). The report highlights that, in the 15 lines evaluated […]

Lina Bautista shines at Africa Fashion Week Peru and is crowned Miss Afro Dominican Republic

Lima, Peru. — The model and journalist, Lina Bautista, stood out in a remarkable way in the renowned Africa Fashion Week Peru, held in the city of Lima, where she was crowned Miss Afro Dominican Republic, raising high the roots, culture and identity of Dominican women internationally. During the event, Bautista shone for his elegance, […]