logo

Rise in Deceptive PDF: The Gateway to Malicious Payloads

ID: bda1756a-3997-5ecd-bf07-813a9da3fcc3

STIX ID: report--bda1756a-3997-5ecd-bf07-813a9da3fcc3

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2024-03-01

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Labs observed a surge in PDF-based delivery of Agent Tesla where malicious PDFs (or embedded JS) lead victims to download obfuscated JavaScript that spawns PowerShell to fetch a large, obfuscated atom.ps1; that script decrypts and loads .NET components which perform AMSI bypass, process injection into legitimate executables (e.g., RegSvcs.exe) to run Agent Tesla, harvest credentials/browser data, exfiltrate via Telegram bots, and establish persistence via scheduled tasks and Run keys. The report includes technical analysis, process trees, persistence artifacts, and hashes/URLs/IPs as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.