A new phishing campaign is targeting mobile users with advanced social engineering tactics and malicious PDF files. The goal is to steal sensitive data.

The phishing messages impersonate the United States Postal Service (USPS) and use a completely new obfuscation technique to deliver the malicious payload.
The new phishing campaign was detected by researchers at Zimperium. Attackers send SMS messages with a malicious PDF file containing a suspicious link. This link redirects users to a fake website to steal sensitive information. The PDF file itself has a complex structure with a header, body, reference table, and trailer. It embeds clickable links without using the standard /URI tag, making analysis more difficult.
See also: Microsoft Teams: New phishing attacks from ransomware gangs
The new obfuscation method involves inserting an XObject into the written URL, creating the appearance of a clickable button. This tactic works in some PDF viewers, such as Chrome and macOS Preview (but may not work in others). When users click the “Click Update” button, they are redirected to a phishing page that says there is a problem with the delivery of a package via USPS. The website asks users to provide some personal information, which is then encrypted and transmitted to a malicious command and control (C2) server.
Researchers discovered more than 20 malicious PDF files and 630 phishing pages. The malicious infrastructure has the potential to impact organizations in more than 50 countries.
Researchers explain that mobile devices still have many security gaps, making them more vulnerable to phishing.
See also: Phishing: PNGPlug Loader distributes ValleyRAT malware

Users and organizations must adopt a multi-layered security approach to combat such attacks on mobile devices:
- Always verify the authenticity of links and attachments before opening them.
- Avoid entering sensitive information on unknown websites or apps that seem suspicious.
- Enable two-factor authentication (2FA) on your accounts and add an extra layer of security, making it harder for attackers to gain unauthorized access.
- Regularly update your device's operating system and applications to fix vulnerabilities that attackers may exploit.
- Avoid public Wi-Fi networks, as they can be easily compromised by hackers. It is recommended to use a virtual private network (VPN) when connecting to public networks.
- Avoid downloading apps from untrusted app stores or unknown sources. These apps may contain malware that can steal sensitive information without your knowledge.
- Always be aware of any unusual activity on your device, such as unexpected pop-ups or changes to settings. If you suspect your device has been compromised, change your passwords immediately and report the incident to the appropriate authority.
See also: Sneaky 2FA: New phishing kit targets Microsoft 365 accounts
Source: www.infosecurity-magazine.com
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
