# Beware: PDF attachments can contain viruses

**URL:** <https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [December 17, 2024, 6:11pm UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762 "2024-12-17T18:11:55Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bullitt](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bullitt/32/5725_2.png) [@Bullitt](https://boards.straightdope.com/u/Bullitt)\
**Post date:** [December 17, 2024, 6:11pm UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/1 "2024-12-17T18:11:55Z")

</div>

Hi, a PSA for today. Apologies if this has been discussed recently.

This morning I received this text —

[![](https://i.imgur.com/Nx1WtMk.png) ](https://i.imgur.com/Nx1WtMk.png)

A quick search yielded these —

[![](https://i.imgur.com/qq15Dqn.png) ](https://i.imgur.com/qq15Dqn.png)

No, I did not click on it!

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [December 17, 2024, 6:16pm UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/2 "2024-12-17T18:16:20Z")

</div>

PDFs can certainly have malicious links, but an actual virus? I’d like to see an example.

---

<div class="post-metadata">

**Author:** ![gnoitall](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@gnoitall](https://boards.straightdope.com/u/gnoitall)\
**Post date:** [December 17, 2024, 6:24pm UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/3 "2024-12-17T18:24:56Z")

</div>

> [@beowulff](#):
>
> I’d like to see an example.

I don’t know about “example”, but here’s here’s the article from Adobe (who invented the format) hinted at in @Bullitt’s post:

[https://www.adobe.com/acrobat/resources/can-pdfs-contain-viruses.html](https://www.adobe.com/acrobat/resources/can-pdfs-contain-viruses.html)

> [@](#):
>
> Can PDFs have viruses?
> 
> Yes, they can. Because PDFs are one of the most universally used file types, hackers and bad actors can find ways to use these normally harmless files — just like dot-com files, JPGs, Gmail, and Bitcoin — to create security threats via malicious code.

---

<div class="post-metadata">

**Author:** ![DocCathode](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/doccathode/32/18773_2.png) [@DocCathode](https://boards.straightdope.com/u/DocCathode)\
**Post date:** [December 17, 2024, 6:30pm UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/4 "2024-12-17T18:30:56Z")

</div>

Disclaimer- I Have Not Read The Article

If Adobe says you can get a virus by downloading a PDF, I’m going to believe them. This really sucks. OTTOMH Septa (the local public transit authority) have a web site that is not intuitive, user friendly, or well designed. All maps and schedules are available for download as PDF’s. Septa’s physical security measures are terribly implemented and inadequate. I see no reason to think their cyber security is any better. They will soon be a hub for virus distribution.

---

<div class="post-metadata">

**Author:** ![Bullitt](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bullitt/32/5725_2.png) [@Bullitt](https://boards.straightdope.com/u/Bullitt)\
**Post date:** [December 17, 2024, 6:33pm UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/5 "2024-12-17T18:33:24Z")

</div>

> [@DocCathode](#):
>
> Disclaimer- I Have Not Read The Article
> 
> This really sucks.

Yes it does suck. JPEGs and PNGs, maybe not yet (a guess), but we’re always texting pictures to each other, right?

Sucks.

---

<div class="post-metadata">

**Author:** ![gnoitall](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@gnoitall](https://boards.straightdope.com/u/gnoitall)\
**Post date:** [December 17, 2024, 6:36pm UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/6 "2024-12-17T18:36:34Z")

</div>

A little more googing found a PDF-vectored virus in CISecurity’s 2024’s Top 10 list:

> **[Top 10 Malware Q1 2024](https://www.cisecurity.org/insights/blog/top-10-malware-q1-2024)**
>
> The Top 10 Malware in Q1 2024 changed slightly from the previous quarter. Here's what the CIS Cyber Threat Intelligence team observed.

> [@](#):
>
> 8. Jupyter
> 
> Jupyter, aka SolarMarker, is a highly evasive and adaptive .NET infostealer. For initial access, the threat actors create watering hole websites to deceive unsuspecting users into downloading a malicious document, often a ZIP or **PDF** file embedded with a malicious executable. Additionally, they use SEO-poisoning to artificially move the malicious website up in search result rankings.

I’ve even heard of Jupyter this year, although I’m only peripherally associated with cyber.

---

<div class="post-metadata">

**Author:** ![Measure\_for\_Measure](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/measure_for_measure/32/557_2.png) [@Measure\_for\_Measure](https://boards.straightdope.com/u/Measure_for_Measure)\
**Post date:** [December 17, 2024, 6:40pm UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/7 "2024-12-17T18:40:06Z")

</div>

Discussion at stackexchange:

> <https://security.stackexchange.com/questions/64052/can-a-pdf-file-contain-a-virus>

Yes, pdf malware is a thing and have been for a long time, but most pdf readers screen for them. Which is why you should keep your .pdf program updated.

PDFs can contain javascript for example.

---

<div class="post-metadata">

**Author:** ![ZipperJJ](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/zipperjj/32/211_2.png) [@ZipperJJ](https://boards.straightdope.com/u/ZipperJJ)\
**Post date:** [December 17, 2024, 6:56pm UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/8 "2024-12-17T18:56:17Z")

</div>

> [@gnoitall](#):
>
> Yes, they can. Because PDFs are one of the most universally used file types, hackers and bad actors can find ways to use these normally harmless files — just like dot-com files, JPGs, Gmail, and Bitcoin — to create security threats via malicious code.

This is very odd wording. A dot-com file? A Gmail file? Is a Bitcoin a file?

---

<div class="post-metadata">

**Author:** ![gnoitall](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@gnoitall](https://boards.straightdope.com/u/gnoitall)\
**Post date:** [December 17, 2024, 7:08pm UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/9 "2024-12-17T19:08:10Z")

</div>

Well, back in the old days of DOS (and CP/M before it), a .com file was an executable program. I don’t know if the command processor in recent Windows releases still recognizes a .com executable.

There was a trend a couple decades ago of using a “.com” executable program embedded in a web page, depending on the confusion with a “.com” website URL.

---

<div class="post-metadata">

**Author:** ![Mijin](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mijin/32/9369_2.png) [@Mijin](https://boards.straightdope.com/u/Mijin)\
**Post date:** [December 17, 2024, 7:27pm UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/10 "2024-12-17T19:27:34Z")

</div>

Bit of a coincidence, as I was googling this just today and landed on Adobe’s answer. In that article they also recommend a website you can use to scan PDFs: [VirusTotal](https://www.virustotal.com/gui/home/upload)

Also, from this thread, I just learned what a [watering hole attack](https://en.wikipedia.org/wiki/Watering_hole_attack) is.

---

<div class="post-metadata">

**Author:** ![blondebear](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/blondebear/32/1022_2.png) [@blondebear](https://boards.straightdope.com/u/blondebear)\
**Post date:** [December 17, 2024, 8:14pm UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/11 "2024-12-17T20:14:39Z")

</div>

I think the first indication of a scam is USPS doesn’t send text messages out of the blue. They have a “text tracking” service but as I understand it you have to initiate contact and provide the tracking number.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [December 17, 2024, 8:41pm UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/12 "2024-12-17T20:41:59Z")

</div>

I think in most cases of stuff written for laymen, the word “virus” just means “bad for your computer” IOW what the pros call “malware” and “malicious content”.

The layman term “virus” does not mean “self-replicating self-spreading executable software” as the pros use the term. On the rare occasions they’re bothering to be precise.

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [December 18, 2024, 12:41am UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/13 "2024-12-18T00:41:24Z")

</div>

Adobe has a _terrible_ record in quality control of its software. Hole, after hole after hole. People looking at these exploits often can’t understand how stupid these mistakes are.

Hence Adobe Flash Player was killed off. And to make sure MS, in one of their updates, auto removed it from customers’ MS-Windows systems. It’s. Just. That. Bad.

In addition to exploiting the programming-like features with the PDF markup language, people also exploit things like buffer overflows and a bunch of other common holes bad programmers don’t properly tend to.

Note that files like GIFs and JPEGs can also contain viruses. E.g., years ago someone found a buffer overflow in the standard LZW decompression library that almost all GIF decoders (and a bunch of stuff) used. Urgent bug fix and rollout ensued.

And it still keeps happening. A couple years ago a [flaw](https://www.digitaltrends.com/computing/hackers-sneak-malware-into-gifs/) was found in the way MS-Teams handled GIFS which allowed people to send a malicious GIF that when shared via MS-Teams allowed malware installation of the receiver’s end.

So, stop using Adobe and such. I use Foxit’s reader.

---

<div class="post-metadata">

**Author:** ![Atamasama](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/atamasama/32/12961_2.png) [@Atamasama](https://boards.straightdope.com/u/Atamasama)\
**Post date:** [December 18, 2024, 1:13am UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/14 "2024-12-18T01:13:14Z")

</div>

Yes, Adobe has been pretty bad about security for decades, and PDF malware has been around for a long time. That’s why, if you use an Adobe product to handle PDFs, you should be very scrupulous about keeping it up-to-date. Or any of them, really. We are an Adobe shop where I work and it’s a constant battle.

> [@ftg](#):
>
> So, stop using Adobe and such. I use Foxit’s reader.

Eh…

> **[Foxit PDF Reader Flaw Exploited by Hackers to Deliver Diverse Malware Arsenal](https://thehackernews.com/2024/05/foxit-pdf-reader-flaw-exploited-by.html)**
>
> Multiple threat actors are exploiting a design flaw inFoxit PDF software to deliver various malware.

> **[Multiple Vulnerabilities in Foxit PDF Reader and Editor Could Allow for...](https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-foxit-pdf-reader-and-editor-could-allow-for-arbitrary-code-execution_2024-105)**
>
> Multiple vulnerabilities have been discovered in Foxit PDF Reader and Editor, the most severe of which could result in arbitrary code execution. Foxit PDF Reader is a multilingual freemium PDF tool that can create, view, edit, digitally sign, and...

Just try to keep your PDF software patched, regardless of which one you use.

(I am personally not a huge fan of Adobe in general so I’m not defending them, but it’s not like you can use Foxit and relax.)

---

<div class="post-metadata">

**Author:** ![Thudlow\_Boink](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/thudlow_boink/32/320_2.png) [@Thudlow\_Boink](https://boards.straightdope.com/u/Thudlow_Boink)\
**Post date:** [December 18, 2024, 1:36am UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/15 "2024-12-18T01:36:57Z")

</div>

> [@DocCathode](#):
>
> If Adobe says you can get a virus by downloading a PDF, I’m going to believe them.

Maybe a nitpick, but Adobe says you can get a virus by _opening_ a PDF, not just by downloading one, assuming I’m reading the article correctly.

---

<div class="post-metadata">

**Author:** ![DocCathode](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/doccathode/32/18773_2.png) [@DocCathode](https://boards.straightdope.com/u/DocCathode)\
**Post date:** [December 18, 2024, 1:38am UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/16 "2024-12-18T01:38:45Z")

</div>

You are technically correct, the best kind of correct to be.

Seriously, you are right. I admit my error.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [December 18, 2024, 1:45am UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/17 "2024-12-18T01:45:36Z")

</div>

That difference is far beyond the tech skillz of 80% of computer/ tablet / phone users.

“Touch it in any way and you’re fuxxored” is close enough for them.

---

<div class="post-metadata">

**Author:** ![Bullitt](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bullitt/32/5725_2.png) [@Bullitt](https://boards.straightdope.com/u/Bullitt)\
**Post date:** [December 18, 2024, 6:26am UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/18 "2024-12-18T06:26:24Z")

</div>

> [@blondebear](#):
>
> I think the first indication of a scam is USPS doesn’t send text messages out of the blue. They have a “text tracking” service but as I understand it you have to initiate contact and provide the tracking number.

Definitely. I was suspicious about that. I was never tempted to click on the PDF.

---

<div class="post-metadata">

**Author:** ![zbuzz](https://avatars.discourse-cdn.com/v4/letter/z/e19b73/32.png) [@zbuzz](https://boards.straightdope.com/u/zbuzz)\
**Post date:** [December 18, 2024, 7:41am UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/19 "2024-12-18T07:41:16Z")

</div>

It’s probably not the actual pdf you have to worry about, it’s that if you tap it, it will take you to a phony USPS page that will instruct you to enter all your personal information.

---

<div class="post-metadata">

**Author:** ![Reply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/reply/32/15952_2.png) [@Reply](https://boards.straightdope.com/u/Reply)\
**Post date:** [December 18, 2024, 7:42am UTC](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762/20 "2024-12-18T07:42:02Z")

</div>

Is the PDF reader baked into Firefox any safer? And I think Chrome has one too now, right? I’m not sure if they are tied into the browser sandbox somehow. Or if they’re generally safer than a standalone desktop app?

[Next page](https://boards.straightdope.com/t/beware-pdf-attachments-can-contain-viruses/1011762.md?page=2)
