PDF carrying an embedded file object released on open
A newly documented banking trojan named Ousaban is targeting users of Spanish and Portuguese banks with fake PDF invoice lures, performing web injects, credential harvesting, and OTP interception to compromise online banking sessions. PDFs are a favorite lure because they can embed file attachments and scripts that many mail filters never unpack: the visible page looks like a legitimate invoice, while an embedded object is released when the victim opens or interacts with it (MITRE T1027.003). Deep CDR parses the PDF's object tree, removes embedded attachments, scripts, and launch actions, and reconstructs a safe PDF that preserves the visible content only. The demo embeds a benign text file in the PDF, so it is safe to open in any environment.
Attack Technique
PDF embedded file attachment
MITRE ATT&CK
T1027.003 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗