Skip to main content
← Back to Demos
PDF Abuse intermediate · 15 min

PDF with embedded JavaScript auto-executing on open

Attackers routinely weaponize PDFs by embedding JavaScript that executes automatically when the document is opened, delivering payloads or phishing lures without any interaction beyond the open action. Malicious scripts can exploit viewer vulnerabilities, trigger external downloads, or exfiltrate local data — behavior aligned with script-based execution techniques such as T1218.001. This demo presents a PDF carrying a benign app.alert script to illustrate the risk without any malicious payload. Deep CDR (Content Disarm and Reconstruction) parses the file, removes all active content including JavaScript, and rebuilds a clean, fully functional PDF that preserves the document's appearance while eliminating the attack surface.

Attack Technique

PDF embedded JavaScript

MITRE ATT&CK

T1218.001 ↗

Platforms

linuxwindows

File Types

.pdf

MetaDefender Capabilities

Deep CDR

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---