Monday, April 13, 2026

Malicious PDFs: how to recognize them and protect yourself from attacks

  • aplicacion - banner 728px

PDFs are simple, widely used files that, in principle, do not raise suspicion. They work on almost any operating system and there is a large amount of free software and websites where you can read and modify them. ESET, a leading company in proactive threat detection, warns that this popularity is one of the reasons why cybercriminals use them as a great tool for deception, and that is why it is essential to be vigilant, verify the origin of the files and adopt good security practices.

A malicious PDF can install or download malware, steal private or sensitive information, or even exploit system or PDF reader vulnerabilities. According to ESET, they are generally distributed as attachments in phishing emails that appeal to urgency, emotion, or concern to induce their opening. According to the latest ESET Threat Report, PDF files are in sixth place in the TOP 10 threat detections, and are one of the trends in attacks through malicious emails.

"Attackers strive to avoid being detected by users and simulate legitimate PDFs. It's easy for them to contain malicious elements that are imperceptible at first glance, especially for users outside of cybersecurity or computer science," comments Fabiana Ramirez Cuenca, Cybersecurity Researcher at ESET Latin America.

Among the most common examples of the different ways they seek to disguise malicious PDFs are:
Purchase or debt invoices, with names like "Invoice.pdf"
Job resumes, mainly in attacks targeting companies
Results of medical studies
Documents linked to financial, banking or governmental entities

One of the most common methods used by attackers is to embed scripts -code snippets- that can be designed to download malware, open remote connections, or execute commands and processes in the background, among other malicious actions. They can also contain hidden links that open when interacting with certain functionalities of the file. In addition, they can exploit some vulnerability or failure of popular readers, such as Adobe Reader, Foxit, among others.

A phishing campaign documented by ESET used PDF files to distribute the Grandoreiro banking trojan. The attack began with a malicious link that led to the download of the infected PDF.

In the spotlight

  • aplicacion - banner 300px

  • banner altices 300x250 junio 2025

Explore more

BFA Consultores celebrates 20 years of experience with a reception at its facilities

BFA Consultores celebrated its 20th anniversary with a reception held at its facilities in the Altos de Las Praderas sector, Distrito Nacional, where it brought together clients, allies, and related parties. The meeting served as a platform to highlight the importance of organized financial management and the timely fulfillment of tax obligations, especially in the […]

The MAP orders to adopt special measures in areas with yellow and green alerts

The Ministry of Public Administration (MAP), in its capacity as the governing body of public employment, ordered the adoption of special administrative measures in the provinces declared in yellow and green alert, in order to preserve the safety of public servants who live in vulnerable areas. In a statement, the MAP informed all bodies and […]

Dollar price in the Dominican Republic this Monday, April 13, 2026

The Central Bank of the Dominican Republic published the reference prices for the purchase and sale of the US dollar for this Monday, April 13, 2026, as follows: In the windows of banks and other financial institutions, the buying rate was RD$58.46, while the selling rate reached RD$61.53. These values represent a daily depreciation of […]

Euro price in the Dominican Republic this Monday, April 13, 2026

The Central Bank of the Dominican Republic published the reference prices for the purchase and sale of the euro for this Monday, April 13, as follows: In banking institutions, the buying rate was RD$67.93, while the selling rate reached RD$72.96. These figures represent a daily depreciation of 0.20% and 0.24% respectively compared to the previous […]

Ministry of Labor suggests telecommuting and flexible hours due to rain

Santo Domingo.- The Ministry of Labor recommended to flexibilize the work day and apply telecommuting in the provinces under alert, as a preventive measure against the rains affecting a large part of the country. The provision covers 26 provinces on yellow alert and two on green alert, where conditions remain conducive to flooding, rising rivers, […]

Trump says that Pope Leo XIV is "terrible in foreign policy" after his criticisms of Iran and Venezuela

New York.- US President Donald Trump lashed out at Pope Leo XIV and said he is «terrible in foreign policy» alluding to his criticisms of Iran and Venezuela, and urged him to «stop pleasing the radical left». "Pope Leo is WEAK on crime and terrible on foreign policy," wrote the leader on his Truth Social […]