The Tax PDF That Every Scanner Declared Clean (It Wasn't)
ID: 70dbccdc-6de2-5337-998e-4b16f822119b
STIX ID: report--70dbccdc-6de2-5337-998e-4b16f822119b
Feed Name: IRONSCALES
**Executive Summary:** A maliciously crafted PDF titled 'Document.pdf' was delivered in a tax-season spearphishing campaign to four mailboxes; the file contained no JavaScript or visible payload but embedded 12 /AA (Additional Actions) tokens that can trigger behavior in PDF viewers, allowing credential-harvesting actions to execute at runtime while evading static analysis and antivirus. Themis flagged the message at 66% confidence based on sender anomalies, timing, sparse email body, and the unusual /AA count; IOCs and recommended detection heuristics (e.g., thresholding /AA counts, behavioral sandboxing, sender context checks) are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
