Attackers sharply expanded the use of malicious PDF files in phishing campaigns, with observed samples rising from 411,800 in 2019 to 5,224,056 in 2020, according to Palo Alto Networks Unit 42. Researchers identified five dominant lure themes: fake CAPTCHA, coupons, play buttons, file sharing, and e-commerce. Fake CAPTCHA PDFs accounted for nearly 40% of observed samples and commonly pushed victims toward browser notification abuse, malvertising, and in some cases malicious Chrome extension installation.
Many of the campaigns relied on traffic redirection to evade takedowns, swap final landing pages, and monetize victims through affiliate-style schemes. File-sharing themed PDFs were also used for credential theft by impersonating services including Dropbox, OneDrive, Atlassian, and Microsoft login pages. The report also published indicators of compromise, redirector domains, final hosts, and YARA rules to help defenders detect several categories of PDF-based phishing activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The report described how many 2020 PDF phishing campaigns used redirector sites to evade takedowns, rotate destinations, and monetize victims through affiliate-style flows. It also published indicators of compromise, redirector domains, final hosts, and YARA rules for several PDF phishing categories.
Using WildFire data collected throughout 2020, researchers classified phishing PDFs into five leading themes: fake CAPTCHA, coupon, play button, file sharing, and e-commerce. The fake CAPTCHA category was the largest, accounting for close to 40% of observed phishing PDFs.
Palo Alto Networks reported that malicious PDF files observed via WildFire increased from 411,800 in 2019 to 5,224,056 in 2020, a 1,160% rise. The report also said PDF malware represented 0.009% of total PDFs in 2019 and 0.08% in 2020.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 73 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.