logo

Purchase order attachment isn’t a PDF. It’s phishing for your password

ID: 223f0a6e-1701-5000-bb34-3d115f3246f8

STIX ID: report--223f0a6e-1701-5000-bb34-3d115f3246f8

Feed Name: Malwarebytes Blog

Threat Score
45/100

Date Published: 2026-03-02

Date Updated: 2026-04-28

...
...

This report details a phishing campaign where a malicious .pdf.htm attachment masquerades as a purchase order; when opened it presents a fake password prompt and silently sends submitted credentials and environment data (IP, geolocation, user-agent) to an attacker via a Telegram bot. The write-up includes screenshots of the email and phishing page, an explanation of the social-engineering technique (encouraging retry after a fake "incorrect password" message), and pragmatic mitigations: verify file extensions, access services via official sites or apps, enable multi-factor authentication, and use up-to-date web/antimalware protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.