logo

Purchase order attachment isn’t a PDF. It’s phishing for your password

ID: c3fb2f5e-2a7a-5621-98f3-8e8c00222965

STIX ID: report--c3fb2f5e-2a7a-5621-98f3-8e8c00222965

Feed Name: Security Boulevard

Threat Score
55/100

Date Published: 2026-03-02

Date Updated: 2026-04-22

Author: Malwarebytes

...
...

This Malwarebytes blog post details a phishing campaign in which a malicious attachment named like “New PO 500PCS.pdf.hTM” opens an HTML page that prompts for credentials, harvests email/password combos plus IP/geolocation and browser details, and exfiltrates them to an attacker-controlled Telegram bot; victims are then shown a bogus invoice image to delay detection. The report highlights indicators (double file extension, browser-based login prompt, Telegram C2), explains attacker behavior, and offers practical mitigations such as checking file extensions, using MFA, and employing updated web-protection/anti-malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.