logo

Insurance Claim PDF Hides JavaScript Behind AcroForm Fields and SendGrid Redirects

ID: 395f3dd6-e26d-5c13-b161-78230eab0ce2

STIX ID: report--395f3dd6-e26d-5c13-b161-78230eab0ce2

Feed Name: IRONSCALES

Threat Score
72/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: [email protected] (Audian Paxson)

...
...

A Spanish-language brand-impersonation phishing campaign delivered an 84 KB PDF (CartaCierreSolicitud.pdf) containing interactive AcroForm fields and compressed/obfuscated JavaScript with /JS and /AA tokens enabling auto-execution; the attacker used a SendGrid tracking redirect (u22037540.ct.sendgrid.net) and controlled the authenticated sending domain (zurichsantandermexico.com.mx) so SPF/DKIM/DMARC passed, and the report lists IOCs (relay IP 167.89.23.152, attachment SHA-256 95b3413da7b8ab587747643e6ed0536e, template token |.TrSite.EMAIL.|) and actionable mitigations such as blocking PDFs with scripting, unwrapping redirects, and treating authentication as insufficient.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.