216.73.217.22

Hidden in Plain Sight: PDF Mishing Attack

· Published 27/01/2025 20:08 · Modified 27/01/2025 20:43

Export JSON

Essential information

Published
27/01/2025 20:08
Modified
27/01/2025 20:43
Tags
2025-01-27 credential-theft pdf phishing
Related entities
200 observables, 9 techniques (mitre), 1 others

Description

A sophisticated campaign targeting mobile devices has been discovered, impersonating the United States Postal Service (USPS). The campaign uses a novel obfuscation technique in files to hide malicious links, making detection difficult for many security solutions. The attack exploits users' trust in documents and leverages advanced social engineering tactics. The malicious PDFs contain hidden, clickable elements that redirect users to pages designed to steal personal and financial information. The campaign's infrastructure includes over 20 malicious files, 630 pages, and potential impact across 50+ countries. The attackers use multilingual support and encryption techniques to expand their reach and protect their operations.

External references