Malicious PDFs: how to recognize them and protect yourself from attacks

  • aplicacion - banner 728px

PDFs are simple, widely used files that, in principle, do not raise suspicion. They work on almost any operating system and there is a large amount of free software and websites where you can read and modify them. ESET, a leading company in proactive threat detection, warns that this popularity is one of the reasons why cybercriminals use them as a great tool for deception, and that is why it is essential to be vigilant, verify the origin of the files and adopt good security practices.

A malicious PDF can install or download malware, steal private or sensitive information, or even exploit system or PDF reader vulnerabilities. According to ESET, they are generally distributed as attachments in phishing emails that appeal to urgency, emotion, or concern to induce their opening. According to the latest ESET Threat Report, PDF files are in sixth place in the TOP 10 threat detections, and are one of the trends in attacks through malicious emails.

"Attackers strive to avoid being detected by users and simulate legitimate PDFs. It's easy for them to contain malicious elements that are imperceptible at first glance, especially for users outside of cybersecurity or computer science," comments Fabiana Ramirez Cuenca, Cybersecurity Researcher at ESET Latin America.

Among the most common examples of the different ways they seek to disguise malicious PDFs are:
Purchase or debt invoices, with names like "Invoice.pdf"
Job resumes, mainly in attacks targeting companies
Results of medical studies
Documents linked to financial, banking or governmental entities

One of the most common methods used by attackers is to embed scripts -code snippets- that can be designed to download malware, open remote connections, or execute commands and processes in the background, among other malicious actions. They can also contain hidden links that open when interacting with certain functionalities of the file. In addition, they can exploit some vulnerability or failure of popular readers, such as Adobe Reader, Foxit, among others.

A phishing campaign documented by ESET used PDF files to distribute the Grandoreiro banking trojan. The attack began with a malicious link that led to the download of the infected PDF.

In the spotlight

  • aplicacion - banner 300px

  • banner altices 300x250 junio 2025

Explore more

Family of Dany Tronilo demand justice after fatal assault in Los Alcarrizos

Family members and friends of the young mechanic Dany Tronilo demanded justice after his death, which occurred during an assault in the vicinity of the Los Patos neighborhood, Los Alcarrizos municipality, Santo Domingo province. The victim received a single gunshot wound with entry and exit, which caused internal bleeding. According to preliminary information, the same […]

Wilson Camacho calls the court's decision in the SeNaSa Case "historic"

Santo Domingo. – Magistrate Wilson Camacho described the court's resolution as a “historic decision”, which accepted the Public Ministry's request and ordered coercive measures for the ten defendants in the SENASA Case, following the investigation of events qualified by Judge Rigoberto Sena as “cruel”, “extremely serious” and even comparable to a form of holocaust. The […]

Court imposes house arrest and pre-trial detention in the Cobra Senasa case

Santo Domingo.— The court hearing the so-called Cobra Senasa case issued important coercive measures this Sunday against several of the defendants in the investigation for alleged embezzlement and corruption within the National Health Insurance (SeNaSa), a scheme that has been described by the Public Ministry as one of the largest administrative frauds investigated in the […]

A girl dies and her mother and grandmother are injured in a hit-and-run on a sidewalk in Palma

Palma. - A 7-year-old girl has died and her mother and grandmother have been injured this Sunday in Palma after a driver ran them over after going up on the sidewalk for reasons that are being investigated, although the first information indicates that the man had lost control of the car. Municipal sources have detailed […]

A JetBlue plane avoids collision with a U.S. military aircraft near Venezuela

New York.- A plane from the American airline JetBlue coming from Curaçao, one of the islands of the Netherlands in the Caribbean Sea off the coast of Venezuela, stopped its ascent to avoid a "collision" with a refueling tanker of the United States Air Force on Friday, and the pilot blamed the military plane for […]

President of Costa Rica congratulates Kast on his victory in the Chilean elections

San José.- The President of Costa Rica, Rodrigo Chaves, congratulated the Chilean people and celebrated the victory of the far-right José Antonio Kast in the second round of the presidential election held this Sunday in the South American country. "I extend my most sincere congratulations to the Chilean people for the holding of the second […]