The Whole Page Is the Button: A PDF Click Trap
ID: 77d5baf5-ba96-5504-ab90-31d246102d1a
STIX ID: report--77d5baf5-ba96-5504-ab90-31d246102d1a
Feed Name: IRONSCALES
A high‑severity phishing campaign used an image‑based PDF with an invisible full‑page pushbutton wired to embedded JavaScript that opens a Firebase-hosted page impersonating Adobe to harvest credentials; SPF/DMARC passed meaning authentication checks did not block delivery, and text obfuscation (soft hyphens and HTML comments) evaded keyword and address extraction. The report includes IOCs (URL, file name, hash, sender domain, and IPs), MITRE mappings, and mitigation guidance emphasizing geometry-aware PDF inspection and normalization of text before rule matching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
