logo

Password-Protected PDFs Are the New Sandbox Killer: How a Compromised .gov Account Delivered an Unopenable Payload

ID: 44b5b70f-ff1a-5530-9756-7b36e64271ab

STIX ID: report--44b5b70f-ff1a-5530-9756-7b36e64271ab

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-03-26

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

Attackers compromised a paraprofessional's government Microsoft 365 account and used it to send a password‑protected PDF (passcode plaintext in the email body) to multiple targets via BCC, allowing the message to pass SPF/DKIM/DMARC while preventing automated scanners from opening the attachment; IRONSCALES' community-driven behavioral detection quarantined the messages and the report recommends flagging passcode-plus-attachment patterns, applying behavioral analysis beyond authentication, and hardening trusted .gov/.edu accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.