A PDF arrives in your inbox with a perfectly ordinary name: Invoice_September.pdf.
You were expecting an invoice, so nothing immediately feels unusual. The sender’s name looks familiar, email is short and professional and there is no strange executable file attached and no obvious warning telling you something is wrong.
So you open it.
That everyday action is exactly why PDFs can be useful to cybercriminals. We tend to think of PDF files as passive documents – contracts, invoices, bank statements, résumés, reports, tickets and forms that we open almost automatically. But a PDF can contain much more than static text and images. Depending on how it has been created and how the PDF reader handles it, a document can contain links, embedded objects, interactive elements and scripts. Attackers can also use PDFs simply as convincing gateways to phishing websites or malicious downloads. This isn’t an obscure attack technique.
Microsoft’s analysis of the Q2 2026 email threat landscape found that HTML and PDF attachments together represented roughly 60–70% of payload-based attacks each month. PDFs alone accounted for approximately 24–31%, consistently making them the second-most common malicious payload type during the quarter. Microsoft also found that credential phishing accounted for 94–96% of payload-based attacks, illustrating an important change in the threat landscape: attackers don’t always need to infect your computer directly if they can persuade you to give them your password instead.
The short answer is yes, PDFs can be used to deliver or facilitate malicious activity. Understanding how they do it is the key to checking documents more safely before opening or interacting with them.
When people hear the phrase ‘PDF virus’, they often imagine opening a document and malware immediately installing itself on the computer. That can be one scenario, particularly where vulnerabilities in outdated PDF-reading software are exploited, but modern PDF attacks can work in several different ways.
A PDF might contain a malicious or deceptive link that sends you to a fake Microsoft 365, Google, banking or company login page. It might contain a button telling you to ‘View Secure Document’, ‘Download Invoice’ or ‘Verify Account’. It might display a QR code designed to move the attack from your computer to your phone. Other attacks can use embedded content, scripts or vulnerabilities in document-reading software as part of a broader infection chain.
Check Point Research reported in 2025 that 22% of malicious email attachments in its research were PDF-based, noting that many attacks were moving away from complicated exploits toward social-engineering techniques involving malicious links and convincing document content.
Sometimes the PDF itself is the weapon, but sometimes it is simply the door the attacker wants you to walk through.
Consider a fake invoice. You open the PDF and see a message saying the document is protected and must be viewed through the company’s secure portal. There is a large ‘View Document’ button. You click it. Your browser opens what appears to be a familiar Microsoft sign-in page. You enter your work email and password. The page may even redirect you somewhere legitimate afterwards, leaving you wondering whether anything unusual happened. Your computer may never have been infected with a traditional virus, but your credentials may now belong to an attacker.
Microsoft documented this broader pattern in its 2026 email research, finding that credential phishing overwhelmingly dominated malicious payload activity compared with traditional malware delivery. This is why asking only, ‘Does this PDF contain malware? is no longer enough. You should also ask; “What is this document trying to get me to do?”
The danger becomes clearer when we look at attacks observed in the wild. During the 2025 U.S. tax season, Microsoft tracked campaigns using tax-themed emails with PDF attachments carrying names that resembled IRS verification forms. In one campaign, the PDF contained a link that passed users through multiple redirects before reaching a fake DocuSign page. Clicking the download option could eventually result in malicious software being delivered to the device.
Microsoft also observed another tax-themed campaign sent to more than 2,300 organizations during February 2025. The emails contained PDFs with QR codes that directed recipients toward infrastructure associated with credential phishing. The messages were designed to look like documents requiring signatures, turning something as routine as opening and scanning a business PDF into the beginning of a phishing attempt.
The lesson isn’t that every invoice, tax document or digital-signature request is dangerous, but that attackers deliberately choose documents we are accustomed to trusting.
The safest time to question a document is before you interact with it. First check the sender and the context.
Were you actually expecting the file? Does this person normally send you documents? Does the email address match the organization it claims to represent? Does the request make sense in the context of your relationship with the sender?
Pay attention to urgency; a message claiming that an invoice must be paid today, a document will expire in an hour, your account will be suspended or your salary information requires immediate verification, is trying to reduce the amount of time you spend thinking.
Next, examine the filename and its actual extension. Attackers can use misleading names, unusual characters or files designed to resemble another format. Microsoft documented a 2025 campaign in which an attachment was named to resemble a PDF even though its actual extension was .svg, a scriptable image format. A familiar-looking filename therefore isn’t proof that the file is what you think it is.
Before opening an unexpected attachment, scan it with trusted security software or a file scanner (part of the ABP Suite of features), capable of checking suspicious documents. In a workplace, follow your organization’s security procedures rather than uploading confidential documents to random online scanning services.
If the sender is someone you know but the message feels unusual, verify it through another trusted channel. A thirty-second phone call can be much cheaper than recovering a compromised account.
Sometimes you genuinely need to open a document, and nothing looked suspicious beforehand. The next layer of protection is recognizing unusual behavior inside the PDF.
Be cautious if a document unexpectedly asks you to enable something, download another file, open an external application, enter credentials, scan a QR code, visit a login page or click a button to unlock content. Ask yourself whether that action makes sense.
Why would an attached invoice require your Microsoft password?
Why would a résumé ask you to download another file?
Why would a bank statement tell you to install software?
Why would a PDF attachment require you to scan a QR code before you can read it?
The more unexpected steps a document introduces, the more reason you have to stop and verify what is happening. Links deserve particular attention. A PDF can display legitimate-looking text while the actual destination points somewhere completely different. If you’re asked to log into an important service, it is generally safer to open the service independently through its official website or application rather than following an unexpected document link.
Not every PDF attack depends on social engineering, software vulnerabilities remain another reason updates matter.
A specially crafted document may attempt to exploit a vulnerability in the software used to process it. Keeping your operating system, browser, PDF reader and security software updated helps close known security weaknesses before attackers can continue exploiting them. Check Point notes that malicious PDFs can use embedded JavaScript or links and, in some cases, exploit vulnerabilities in outdated PDF reader software.
That means an old PDF reader isn’t simply inconvenient software sitting on your computer, but can become part of your attack surface. Automatic updates are therefore one of the simplest security habits you can adopt.
Modern antivirus and anti-malware protection can detect many known and suspicious files, including malicious documents. Microsoft Defender, for example, maintains specific detections for PDF-related phishing threats. AVP Suite also does the same, and it comes with a browser-first extension application. No security product should be treated as permission to open every attachment without thinking.
A PDF may contain no conventional malware at all, and instead link to a newly created phishing website. Another campaign might use previously unseen techniques. A legitimate account could be compromised and used to send a malicious document, making the sender appear trustworthy. That is why real-time malware protection, file scanning, phishing protection and human judgment work better together than any single layer alone.
Treat context as more important than the display name. Email accounts can be compromised, attackers can impersonate colleagues, suppliers, customers and executives. A malicious attachment arriving from a familiar conversation can therefore feel much more convincing than obvious spam.
If your colleague who normally sends monthly spreadsheets suddenly emails an unexpected PDF asking you to sign into a portal, don’t assume familiarity equals safety – ask them.
Similarly, if a supplier unexpectedly changes payment instructions inside a PDF invoice, verify those changes using a previously known phone number or contact method rather than the information contained in the message. Trust should come from verification, not familiarity alone.
A safer approach to documents begins before you click. AVP Suite’s Threat Scanner can help users check suspicious files and URLs before deciding whether to interact with them. That becomes particularly useful when an unfamiliar attachment arrives through email, messaging platforms or a download and you’re uncertain whether it should be trusted.
The protection shouldn’t end with the file itself. If a PDF attempts to direct you toward a suspicious website, Safe Browsing and Suspicious URL Protection provide another layer around the browsing experience, while real-time malware protection helps defend the device against malicious software.
This layered approach matters because PDF attacks don’t all behave the same way. One may contain something malicious, another may lead to somewhere malicious, while a third may simply convince you to voluntarily hand over information. The security needs to follow the entire journey.
PDFs aren’t inherently dangerous. Billions of legitimate documents move between people and organizations every day, and the format remains fundamental to modern digital communication. That familiarity, however, is exactly what makes it useful to attackers. The next time an unexpected PDF lands in your inbox, resist the instinct to open it simply because the file format looks harmless.
Check who sent it and ask whether you expected it. Look at the real file extension, scan suspicious documents and keep your software updated. Be cautious of links, QR codes and unexpected login requests. If something doesn’t make sense, verify it before continuing. The most dangerous part of a malicious PDF isn’t always what happens when you open the document, but what it convinces you to do next.
Can a PDF contain a virus?
Yes. PDFs can be weaponized through malicious content, links, scripts, embedded elements or exploitation of vulnerabilities in document-reading software. They can also act as the first stage of a phishing or malware-delivery attack.
Can opening a PDF infect my computer?
It is possible, particularly if a malicious document exploits a software vulnerability. However, many current attacks require additional interaction, such as clicking a link, downloading another file or entering credentials into a phishing page.
How can I check if a PDF is safe before opening it?
Verify the sender, check whether you expected the document, examine the actual file extension, scan suspicious files with trusted security software and avoid opening attachments that arrive with unusual or urgent requests.
Can a PDF steal my password?
A PDF can be used to direct you to a phishing page designed to steal passwords. The PDF itself may contain no traditional malware, which is why links and login requests inside documents deserve particular caution.
Are QR codes inside PDFs safe?
QR codes are simply another way of directing you to a destination. Microsoft documented phishing campaigns using QR codes embedded in PDF attachments to send users to credential-stealing websites.
How does AVP Suite help with suspicious documents?
AVP Suite’s Threat Scanner can help evaluate suspicious files and URLs, while Safe Browsing, Suspicious URL Protection and malware protection provide additional layers when a document attempts to lead users toward unsafe websites or malicious content.