Online malware - Inside PDF Malware Attacks - eWeek Security Watch

Inside PDF Malware Attacks

Written By
Brian Prince
Brian Prince
Sep 22, 2010
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Malicious PDFs have become familiar features on the threat landscape, in no small part due to the popularity and ubiquity of Adobe Reader and Acrobat.

In a new report, researchers at Symantec took a deep look at how malicious PDF attacks hit users. According to Symantec, in the span of a year, the United States was the favored country to attack with PDF malware. In January, 59 percent occurred in the U.S., researchers found.

“Attackers use a variety of different channels to deliver malicious PDF files,” according to the report. “The threat landscape is dominated by three main channels, which are mass-mailing, drive-by downloads, and targeted attacks.”

Attackers sometimes pack junk parts into the malicious files in order to throw off antivirus software, Symantec found. Others times, they take advantage of Adobe Systems’ support for encryption to protect PDF documents. Malware authors use this feature to protect malicious content from being scanned by antivirus engines. There have also been examples of malicious JavaScript being broken into multiple small chunks of data and then concatenated together.

“We have seen an ever increasing use of PDFs for malicious purposes over the past two years,” blogged Fred Gutierrez, threat analyst for Symantec Security Response, who co-authored the report. “During this time, we have tracked the growth and usage and have been constantly improving our detections to handle the different evolutions of these threats. We see new vulnerabilities related to PDF readers discovered on a regular basis, often being exploited in-the-wild before a patch is available.”

The report can be downloaded here (PDF).

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.