Skip to main content
← Back to Demos
PDF Abuse intermediate · 15 min

PDF carrying an embedded file object released on open

A newly documented banking trojan named Ousaban is targeting users of Spanish and Portuguese banks with fake PDF invoice lures, performing web injects, credential harvesting, and OTP interception to compromise online banking sessions. PDFs are a favorite lure because they can embed file attachments and scripts that many mail filters never unpack: the visible page looks like a legitimate invoice, while an embedded object is released when the victim opens or interacts with it (MITRE T1027.003). Deep CDR parses the PDF's object tree, removes embedded attachments, scripts, and launch actions, and reconstructs a safe PDF that preserves the visible content only. The demo embeds a benign text file in the PDF, so it is safe to open in any environment.

Attack Technique

PDF embedded file attachment

MITRE ATT&CK

T1027.003 ↗

Platforms

linuxwindows

File Types

.pdf

MetaDefender Capabilities

Deep CDR

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---