logo

The PDF That Passed Every Scan Without Being Read

ID: 841b0749-6264-59ea-8b7e-a847b90a92b0

STIX ID: report--841b0749-6264-59ea-8b7e-a847b90a92b0

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: [email protected] (Audian Paxson)

...
...

A targeted phishing email to a regional healthcare organization used CR/LF control characters in a PDF filename to cause file extraction pipelines to produce a zero-byte decoy while the actual 376 KB PDF payload was stored in a .b64 sidecar and not scanned; authentication signals collapsed across relays, IRONSCALES detected the message via behavioral and authentication anomalies, and the report provides IOCs and mitigation steps such as auditing filename control-character handling, layering authentication into attachment risk scoring, and decoding/scanning base64 sidecars.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.