Cybersecurity researchers at Cisco Talos have exposed a growing trend in PDF‑based phishing attacks where hackers impersonate major brands like Microsoft and DocuSign to lure victims into placing malicious calls. These campaigns, running from May 5 to June 5, 2025, blend familiar visual elements with telephone‑oriented attack delivery (TOAD), creating a highly effective form of social engineering.
What’s Going On?
Attackers send phishing emails that appear to come from trusted brands. Each email contains a PDF attachment crafted with official-looking branding and instructions that pressure the recipient to “call support.” On the surface, the message may appear to offer account verification or transaction support, but it conceals a VOIP-controlled number linked to threat actors.
Inside the PDFs, recipients may also find QR codes or embedded links redirecting to fake login portals. These use PDF annotations like sticky notes or form fields, making them appear as legitimate customer service prompts. Once a target calls the number, a cybercriminal adopts the persona of a support representative, equipped with scripted dialogues, spoofed caller IDs, and even hold music that lends credibility to the interaction.
Why It Works So Well
This TOAD approach works by exploiting our trust in phone communication. While email phishing has become widely understood, receiving a call feels more trustworthy—and attackers here exploit that vulnerability. Live conversations enable real-time manipulation of emotions, urgency, and compliance during the call.
Tangibly harmful outcomes follow. Some attackers push for banking trojans on Android, while others install remote access tools on PCs, granting persistent control. The FBI has flagged a group called Luna Moth, using similar tactics—posing as IT staff to infiltrate networks.
Brands Under Fire
During the analyzed period, Microsoft and DocuSign were the most frequently spoofed brands via PDF‑based phishing. Other targets included NortonLifeLock, PayPal, and Geek Squad. Additionally, attackers are creatively twisting PDFs using annotations to embed QR codes that masquerade as legitimate links, pointing to credential-harvesting sites or fake Microsoft login pages.
Technical Tactics & Innovation
- PDF Annotation Abuse: Hackers insert QR codes and links through sticky notes or form fields, creating fake yet convincing prompts.
- VoIP and Spoofed Caller IDs: To preserve anonymity and replicate a genuine support line, attackers rely on VoIP numbers and reuse them for days, enabling multi-step attacks.
- M365 Direct Send Exploitation: Some campaigns utilize Microsoft 365’s “Direct Send” feature, enabling internal-looking emails that bypass standard email filters—targeting over 70 organizations since May.
A Broader Phishing Context
This isn’t an isolated trend. Earlier campaigns have used malicious PDFs to carry banking or credential‑stealing payloads. But TOAD represents a more insidious evolution—extending the phishing conversation from email to live phone interaction. By scripting non‑threatening issues and then guiding victims to install remote access tools or fake payment pages, attackers significantly broaden their attack surface.
Defense Is a Process, Not a Feature
According to Talos, brand‑impersonation detection engines are essential in defending against these threats. Additional recommendations for organizations and individuals include:
- Multi‑Factor Authentication (MFA) – This adds an extra record layer if credentials are compromised.
- Caller Verification Protocols – Never share personal or system details with unsolicited callers, even if they claim to be from a trusted company.
- Employee Awareness Training – Equip teams to recognize PDF-based phishing tricks and TOAD methods.
- Advanced Email Filtering – Especially to catch anomalies from Direct Send or internal-looking messages.
- PDF Sandboxing and Scanning – Analyze clickable elements in attachments before opening or activating them.
Final Thoughts
The emergence of TOAD via PDF-based phishing highlights how threat actors are linking digital deception with live conversations to build trust and overcome user skepticism. The seamless blend of document lures and human interaction increases the attack’s potency, making it harder to detect and resist.
In response, organizations must adopt layered defenses—leveraging AI‑driven brand impersonation checks, thorough PDF analysis, call‑screening protocols, and robust training. For individuals, the key takeaway is simple: if you receive an unexpected email urging you to call for help, disengage—and contact the company directly through verified channels.
By maintaining skepticism and layered defenses, users and organizations can significantly reduce the success of these increasingly sophisticated phishing schemes.
Please subscribe to the Newsletter so that you do not miss any critical update
