PDF Launch Action Executes External Program
PDF documents can carry an OpenAction that fires automatically when the file is opened, and a Launch action can invoke an external application — a behavior attackers abuse to execute malware the moment a victim opens a document. Combined with JavaScript, these actions can chain commands that download and run payloads while the reader appears to display a harmless page. This demo uses a benign PDF whose Launch action only opens the Calculator app, reproducing the technique with zero risk. MetaDefender Deep CDR sanitizes the PDF, removing OpenAction and Launch entries along with all active content, and rebuilds a clean, fully functional document that cannot execute anything.
Attack Technique
PDF Launch action
MITRE ATT&CK
T1218.001 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗