Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Phishing - PDFs: The New Frontier of Phishing
Phishing Attacks Latest News News & Analysis Social Engineering

PDFs: The New Frontier of Phishing

Kirsten DoyleBy Kirsten DoyleJuly 3, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
PDF Phishing
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Brand impersonation is nothing new. But Cisco Talos says it’s showing up in increasingly creative forms—especially within PDF attachments. 

A recent update to Cisco’s intelligence brand impersonation detection engine now expands its reach. It picks up a broader array of email threats where trusted brand names arrive not in plain text, but tucked inside PDF payloads. Some even come armed with QR codes or clickable annotations. Others skip links altogether and simply urge the victim to call a phone number. 

It’s a subtle twist on an old scam. And it’s working.  

Callback Phishing Via PDF 

This isn’t your average phishing campaign. Many of these PDFs carry what Talos calls Telephone-Oriented Attack Delivery, or TOAD. The document prompts the recipient to dial a number, often VoIP, frequently reused, and controlled by the attacker. Once on the line, the victim is met with a convincing voice, posing as someone from Geek Squad, PayPal, or another familiar name. 

There’s no malicious link to click. Just a phone call. And that makes it harder to detect using traditional defenses. 

The live interaction allows the attacker to manipulate emotions and responses in real-time, Talos researchers explain.  It’s phishing without the phishhook, no spoofed login pages or fake captchas required. 

Still, those are in play too. Some emails combine tactics: impersonating Microsoft, Adobe, or DocuSign via embedded logos, QR codes, and layered payloads that bypass keyword-based spam filters. 

The Versatility of PDFs 

It’s the versatility of PDFs that makes them such an effective delivery method. Their structure allows for multiple layers of content, such as text, images, annotations, and even hidden URLs. Attackers are using every inch of that real estate. 

One PDF may show a familiar company logo. Another hides a shortened URL in a sticky note or form field. Some mimic official documents, uploaded and sent through Adobe’s e-signature service to add a sheen of legitimacy. And because PDFs render on open, trusted platforms like Adobe Reader, most recipients don’t think twice before opening them. 

QR codes are another favorite. They blend naturally into documents and, once scanned, redirect the user to phishing pages, often protected by CAPTCHA screens to appear more secure and delay detection. 

Talos has even tracked phishing emails with multiple embedded links. A visible QR code leads to a benign page, while an annotation hides the real threat. It’s sleight-of-hand, built into the file. 

Brands Under Fire 

Cisco’s data paints a clear picture: between May 5 and June 5, Microsoft and DocuSign were the most spoofed brands in phishing emails with PDF attachments. For TOAD-style attacks, the names NortonLifeLock, PayPal, and Geek Squad top the list. 

In one case, Talos found a VoIP number, +1-818-675-1874, used in TOAD scams for four days straight. The repeat usage isn’t random. It allows malefactors to set appointments, follow up with targets, and keep a consistent brand persona. It’s also cheaper. 

These operations aren’t localized. An IP map of recent attacks shows sources across multiple regions, pointing to distributed infrastructure and possibly global scam call centers. 

Exploiting Psychological Tendencies 

Javvad Malik, Lead Security Awareness Advocate at KnowBe4, says: “By impersonating trusted government agencies with well-crafted  PDFs, criminals are exploiting our psychological tendency to comply with authority figures. This aligns with KnowBe4 Threat Labs’ research showing how attackers consistently exploit trusted platforms and brands. The 2025 Phishing Threat Trends Report revealing that 62.6% of phishing attacks now use brand display impersonation to establish credibility.” 
 
What’s particularly concerning is how these attacks exploit mobile device limitations, where reduced screen visibility makes scrutiny more difficult, Malik adds. “KnowBe4’s data shows that 76.4% of phishing attacks now employ polymorphic features to evade detection, and these PDF-based government impersonations represent another tactic.”  

A Resurgence of TOADs 

Lucy Finlay, Director, Secure Behaviour and Analytics, at Redflags from ThinkCyber adds that TOADs are nothing new, but their resurgence recently has been notable. “This evolution is accelerated by the use of AI to identify legitimate login URLs of well-known brands that are vulnerable to takeover and imitation.  Pair this with the fact that “attackers imitate real support workflows,” and the usual emotional manipulation is present; it’s extremely hard for the victim to use traditionally taught security awareness techniques to detect the scam.” 

She says this is why security training needs to be integrated into daily workflows, and nudging at the point of risk is an effective way to do this. “For example, if the victim receives an email from an address that looks extremely plausible as a known brand, and contains a malicious link or attachment, a nudge on these elements to urge caution may be enough to stop the victim from going on to respond to the attempt.“ 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories
  • Kirsten Doyle
    Dutch police, NCSC take down major botnet
  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}