Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

This new phishing kit turns PDF files into malware – here’s how to stay safe

Tech Wavo by Tech Wavo
October 2, 2025
in Computers
0




  • MatrixPDF phishing kit weaponizes PDFs using embedded JavaScript and redirect mechanisms
  • It mimics legitimate tools, offering drag-and-drop import, content blur, and Gmail bypass features
  • To stay safe, disable JavaScript, avoid suspicious PDFs, and use advanced email security tools

A new PDF phishing kit is being sold on the dark web, promising customers advanced features, a simple interface, and competitive pricing, experts have warned.

Security researchers from Varonis spotted MatrixPDF, an advanced solution being advertised as a legitimate tool, despite being circulated around the dark web.

Its full name is MatrixPDF: Document Builder – Advanced PDF Phishing with JavaScript Actions. It is being advertised as an “elite tool for crafting realistic simulation PDFs tailored for black teams and cybersecurity awareness training.”


You may like

How to defend

“With drag-and-drop PDF import, real-time preview, and customizable security overlays, MatrixPDF delivers professional-grade phishing scenarios,” the ad reads.

“Built-in protections-such as content blur, secure redirect mechanism, metadata encryption, and Gmail bypass-ensure authenticity and reliable delivery in testing environments.”

With MatrixPDF, users can add a URL to the PDF, to which the victims will be redirected.

They can add titles, custom icons, and blur the content to look like it is “protected” against unauthenticated viewers. But its key feature is embedding JavaScript.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Users can toggle on JavaScript actions inside the PDF, which are triggered when the file is either opened or clicked. The payload URL, specified beforehand, can then be opened automatically, as soon as the file is clicked.

MatrixPDF can also be used to simulate system dialogs and display custom alert messages. All these things “effectively turn the PDF into an interactive lure,” the researchers concluded.

The best way to defend from weaponized PDF files is to avoid clicking prompts in unexpected and unsolicited PDF attachments.


You may like

This is especially important if the files have “Open Secure Document” buttons or blurred overlays.

Users can also disable JavaScript in the PDF reader which blocks embedded scripts, and ultimately – keep both your email client and PDF reader up to date.

Finally, using advanced email security tools, such as AI-powered filters, can detect suspicious overlays, hidden links, and malicious redirect behaviors.

Via BleepingComputer

You might also like

Previous Post

All Amazon Fire tablets drop to record-low prices!

Next Post

Here’s how you can try the Meta Ray-Ban Display glasses (in a couple of months when slots are available)

Next Post
Here’s how you can try the Meta Ray-Ban Display glasses (in a couple of months when slots are available)

Here’s how you can try the Meta Ray-Ban Display glasses (in a couple of months when slots are available)

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Jeff Bezos’ Blue Origin Wins Contract to Take NASA Rover to the Moon

by Tech Wavo
October 2, 2025
0
Jeff Bezos’ Blue Origin Wins Contract to Take NASA Rover to the Moon
Computers

NASA’s VIPER lunar rover could be delivered to the moon by Blue Origin, Jeff Bezos’ aerospace company. The US space...

Read more

IT Resume Clarity: Separate Actions and Accomplishments to Tell a Clear Story

by Tech Wavo
October 2, 2025
0
IT Resume Clarity: Separate Actions and Accomplishments to Tell a Clear Story
Technology

Lateat guestBy J.M. Auron Quantum Tech Resumes In my previous article, I recommended against using an all-bulleted resume format—because it’s...

Read more

These 3 new Prime Video shows will make you wish you spent less time binging The Summer I Turned Pretty – stream them now

by Tech Wavo
October 2, 2025
0
These 3 new Prime Video shows will make you wish you spent less time binging The Summer I Turned Pretty – stream them now
Computers

There might be a whole host of new films on Prime Video in October 2025, but it's the streamer's TV...

Read more

Why Did AbCellera’s Stock Jump Over 7% After Hours? – AbCellera Biologics (NASDAQ:ABCL)

by Tech Wavo
October 2, 2025
0
Why Did AbCellera’s Stock Jump Over 7% After Hours? – AbCellera Biologics (NASDAQ:ABCL)
Financial

AbCellera Biologics Inc. (NASDAQ:ABCL) shares are trading on Thursday.Check out the current price of ABCL stock here.After-Hours Trading ActivityShares of...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock