MatrixPDF is a newly discovered phishing and malware deployment toolkit that allows cybercriminals to weaponize ordinary PDF files for malicious purposes. The toolkit was first identified by Varonis researchers on cybercrime forums, where it is marketed as both a phishing simulation and a blackteaming tool. MatrixPDF enables attackers to import legitimate PDF documents and augment them with a variety of deceptive features, including fake secure document prompts, custom icons such as padlocks or corporate logos, and content blur overlays that obscure the real content until the user interacts with the file. One of the most dangerous aspects of MatrixPDF is its ability to embed JavaScript actions within the PDF, which can execute code when the document is opened or when a user clicks on specific elements. This functionality allows attackers to redirect victims to external payload URLs, leading to credential theft or malware downloads. The toolkit is designed to bypass common email security filters, particularly those used by Gmail, by making the malicious PDFs appear routine and trustworthy to recipients. MatrixPDF offers a drag-and-drop interface, real-time preview, and customizable security overlays, making it accessible even to less technically skilled threat actors. The tool is sold under various pricing plans, ranging from $400 per month to $1,500 per year, and is distributed via cybercrime forums and Telegram. Built-in protections such as metadata encryption and secure redirect mechanisms are advertised to enhance the authenticity and delivery reliability of the malicious PDFs. The toolkit's features are specifically tailored to evade detection and increase the likelihood of successful phishing or malware campaigns. Attackers can specify payload URLs that the PDF will invoke, enabling seamless redirection to phishing sites or malware downloads after victim interaction. The use of overlays and blurred content further enhances the social engineering aspect, tricking users into believing they are unlocking a secure document. MatrixPDF's emergence highlights the ongoing evolution of phishing tactics, leveraging trusted file formats and sophisticated obfuscation techniques. Security researchers warn that the toolkit's ease of use and effectiveness could lead to a surge in PDF-based phishing and malware attacks targeting both individuals and organizations. Organizations are advised to update their email security protocols and educate users about the risks associated with opening unsolicited PDF attachments. The discovery of MatrixPDF underscores the need for continuous vigilance and advanced threat detection capabilities to counter increasingly sophisticated social engineering tools.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Security researchers reported on MatrixPDF, a toolkit that weaponizes PDF attachments to deliver phishing pages and malware lures, with Gmail users highlighted as a target. The reporting describes the toolkit's use of malicious PDFs as an initial access and social-engineering mechanism.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.