Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes – how to stay safe
- A new phishing campaign is targeting businesses and individuals in over 50 countries
- Experts warn attackers are hiding malicious links in PDFs using a never-before-seen obfuscation technique
- Use the best antivirus software and activate advanced mobile threat defense solutions
PDF files, long considered a safe and reliable way to share documents, are now being weaponized by cybercriminals in a sophisticated phishing campaign targeting mobile users.
New research from Zimperium’s zLabs team claims this new threat involves malicious PDFs delivered via SMS messages whose senders impersonate the United States Postal Service (USPS).
Attackers are using advanced techniques to hide malicious links within the files, exploiting the trust users place in the format to steal sensitive data.
Why mobile users are vulnerable
This campaign reportedly targets organizations and individuals in over 50 countries with over 20 malicious PDF files and 630 phishing pages identified so far.
Attacks commence once the victim clicks on the malicious link hidden in the PDF; usually containing requests for personal information, including names, addresses, and credit card details.
Mobile devices are considered especially vulnerable to this type of attack because, on smaller screens, users have limited visibility into file contents before opening them.
Malicious links in these PDFs are even more difficult to detect than usual, because the attackers aren’t using the standard /URI tag to embed links, allowing the malicious content to evade detection by traditional endpoint security software.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“Although USPS has no involvement, cybercriminals exploit its trusted name to mislead and target users,” said Nico Chiaraviglio, Zimperium zLabs’ Chief Scientist.
“This campaign shows the growing sophistication and continued rise of mishing attacks, emphasizing the need for proactive mobile security measures,” he added.
How to protect yourself
One of the most effective ways to stay ahead of this type of attack is to verify the sender’s details, and the metadata of any attachment you open; even more important measures to take as business email attacks are becoming a bigger threat than ever for businesses.
You may also want to avoid clicking on links embedded in PDFs or SMS messages. Instead, navigate directly to the official website or use the organization’s mobile app.
Furthermore, to stay safe from malware on mobile devices, ensure you’re using the best Android antivirus or best iPhone antivirus software.
You may also like
A new phishing campaign is targeting businesses and individuals in over 50 countries Experts warn attackers are hiding malicious links in PDFs using a never-before-seen obfuscation technique Use the best antivirus software and activate advanced mobile threat defense solutions PDF files, long considered a safe and reliable way to share…
Recent Posts
- Steam Machine and Steam Frame are coming ‘this summer’
- Valve says it’s ready to launch the Steam Machine this summer
- Best Buy slashes up to $400 off Apple tech in a limited-time sale — get AirPods, MacBooks, iPads and Apple Watches from $99.99
- The Instagram Plus subscription has officially launched
- Cyberdecks used to look like little laptops, but now they’re getting more personal
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023