Malicious PDF Invoices Used in Cross-Platform Cyberattacks

Malicious PDF Invoices Used in Cross-Platform Cyberattacks

A new wave of advanced email-based cyberattacks is leveraging deceptive PDF invoices to infiltrate systems across Windows, macOS, and Linux platforms.

Masquerading as routine billing notices, these emails exploit trust in familiar business workflows, luring recipients into opening PDFs that serve as launch points for delivering Remote Access Trojans (RATs). Though Windows remains the primary target, devices running Java Runtime Environment (JRE) on macOS and Linux are also vulnerable.

Once executed, the malware provides attackers with comprehensive system access—allowing them to monitor user activity, capture keystrokes, browse files, and even activate microphones or webcams remotely.

What makes this campaign particularly insidious is its use of legitimate email infrastructure. By taking advantage of the Spanish mail provider serviciodecorreo.es—a service authorized by many domains for sending email—the messages bypass standard SPF checks and appear genuine.

Inside the attached PDFs, users are prompted to interact with disguised buttons, setting off a multi-stage infection process that quietly embeds the RAT and grants attackers long-term control.

Attack Delivery Path (Attribution: Fortinet)

The threat actors behind this campaign manipulate human behavior by inducing urgency, deliberately disrupting decision-making to increase the likelihood of a click.

According to Fortinet analysts, the operation incorporates an array of stealth mechanisms: trusted cloud storage services such as Dropbox and MediaFire are co-opted to distribute payloads; geographic targeting filters traffic to specific regions; and Ngrok tunnels cloak command-and-control communications, making detection significantly harder for traditional defenses.

Weaponized File-Sharing and Adaptive Malware Delivery Tactics
(Research attribution: Fortinet)

Threat actors in this campaign have taken a calculated, reconnaissance-driven approach, selecting exploitable domains and leveraging legitimate platforms to slip past traditional defenses. One notable tactic involves embedding malicious links hosted on trusted services like MediaFire—blending in seamlessly with normal web traffic.

Once a victim interacts with the deceptive file, a Java-based Remote Access Trojan (RAT) named RATty is unleashed. This malware grants full administrative access, enabling attackers to execute arbitrary commands, log keystrokes, take screenshots, and siphon off sensitive data—posing an acute threat to enterprise environments.


Dissecting the Infection Flow: Deception by Design

The attack kicks off with a tampered PDF invoice that tricks the user into thinking it failed to render properly. A prompt encourages them to “resolve” the issue by clicking a button that redirects to a Dropbox-hosted HTML file titled Fattura (Italian for “invoice”).

Upon opening, the HTML file mimics a CAPTCHA-like validation—featuring the phrase “Sono un essere umano – Verifica” (“I am a human – Verify”)—before seamlessly rerouting the user to a concealed Ngrok tunnel.

Here’s where the sophistication deepens: the attackers deploy advanced geolocation filtering. Italian users are served a malicious Java Archive (JAR) file disguised under bland names like FA-43-03-2025.jar, while non-targeted users are handed an innocuous Google Drive-hosted invoice tied to Medinova Health Group. This selective targeting not only amplifies attack precision but also acts as a smokescreen for evading security sandboxing.

Because many email and web security tools operate from cloud regions or generic environments, they receive only the benign content—allowing the malware’s core delivery mechanism to stay beneath the radar.

The final result: an undetected RAT installed on systems running any OS with Java support, with attackers gaining persistent, high-privilege remote access—an alarming demonstration of the evolving complexity of cross-platform cyber threats.

More Articles & Posts