A new phishing and malware kit called MatrixPDF allows attackers to transform ordinary PDF files into realistic, interactive “bait” files that bypass some security mechanisms and redirect recipients to credential-sniffing pages or malware downloads. The existence and capabilities of MatrixPDF are documented in a recent analysis by researchers at Varonis.
What does MatrixPDF do — a technical overview
MatrixPDF works as a “ document builder ”: the attacker can upload a seemingly legitimate PDF and add features such as blurred content that appears to be “ protected ”, fake “ Open Secure Document ” prompts , and clickable overlays that lead to external URLs. In addition, the tool supports embedding JavaScript actions that are triggered either when the document is opened or when the user clicks a button — resulting in opening an external website or other actions in the user interface .
See also: Datzbro: New Android trojan scams elderly people

Where it was found and how it is distributed
The developer of MatrixPDF promotes the kit as simulation a phishing and blackteaming tool . However, Varonis researchers have spotted MatrixPDF on cybercrime forums, and have observed that the creator/seller also promotes it via platforms such as Telegram, offering subscription packages with different prices (from monthly packages to annual licenses).
Why PDFs are attractive to attackers
PDFs remain an accepted and widely used document format — many email systems display them inline without requiring external actions. MatrixPDF leverages this trust: because the PDF file itself does not contain executable files, many scanning systems do not immediately recognize malicious content. Instead, the offensive behavior occurs when the user clicks on the embedded elements and the malicious payload is loaded externally — an approach that can bypass the filters of some email providers.
See also: Hackers approached BBC journalist for help in hack

Attack practices — usage examples
In practical tests reported in the analysis, a malicious PDF was able to reach a Gmail account without being detected by phishing filters — because the PDF only triggers the attack after user action. In addition, some features seek to “obfuscate” the content to convince the user that they must click to “reveal” the document, increasing phishing success rates.
Impacts and risks for businesses
The use of such tools means that organizations face an increased risk of successful spear-phishing attacks: attackers can target specific departments, create realistic “business” documents, and combine the technique with social engineering. Furthermore, platforms such as Telegram have repeatedly been documented as communication and data extraction channels for phishing kits and bots, which accelerates the adoption and distribution of these packages.
See also: Critical vulnerability in My Cloud NAS devices allows malicious code execution

How organizations and users can protect themselves — practical defenses
- Enhance PDF content analysis: Email security should structurally analyze PDFs, detect blurry overlays, fake prompts, and sandbox embedded URLs before allowing delivery.
- Link isolation policies: Where possible, convert external links to safe redirectors that are checked before loading.
- Training and testing: Customized awareness tests should include PDF-based phishing scenarios so staff can recognize warning signs.
- AI/ML technologies: Modern solutions that apply AI to analyze PDF structure and simulate loading external resources can reduce the likelihood of such attacks being delivered.
See also: New Spear-Phishing Attack Distributes DarkCloud Malware
MatrixPDF is a reminder that attackers no longer need to hide executables within files to bypass security — clever, interactive documents that exploit user trust and email platform. The response requires a combination of technological detection, isolation policies, and ongoing user education.
Source: www.bleepingcomputer.com
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
