Phishing PDF Drops Malware Via Fake Edge Loader

The Hacker News · High sophistication
Last updated September 3, 2026

Researchers describe BraZetsu, a Windows malware framework used by an initial-access broker to turn infected PCs into "access for sale" on a criminal marketplace. While the malware itself is technical, the article includes real-world delivery details pointing to phishing: victims are tricked into opening a PDF and visiting a malicious website that drops a script and ultimately runs an EXE payload.

Key findings

  • BraZetsu is positioned as an initial-access toolkit that helps sell access to infected Windows systems via an underground "access-as-a-service" marketplace.
  • The likely infection route is social engineering, starting with a loader that masquerades as Microsoft Edge and is downloaded from a specific domain.
  • A related, documented campaign (Ousaban) used an email-delivered phishing PDF to push victims to a malicious site that checks geography (Spain/Portugal) before dropping a VBS script and then an EXE payload.
  • The article also references other real lure themes used in the region, including invoice-themed attachments and phishing that impersonates judicial summons.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounts Payable, Treasury, Procurement, Legal, HR, Executive Assistants, All employees in Spain/Portugal/Brazil operations.
  • Affected industries: Financial services, E-commerce, Corporate / general business, Industrial, Law enforcement / government.
  • Attack channels: email, website.
  • Impersonated: A business sender requesting the user view a PDF (phishing), Billing/Invoice sender (vendor or accounts receivable), Court / judicial authority.

Awareness takeaways

  • Treat PDFs that push you to click a link and download another file as highly suspicious; report instead of proceeding.
  • Block and report unexpected script downloads (e.g., .VBS) and do not run files downloaded from a website prompted by an email.
  • Be extra cautious with common business lures (invoices, legal notices) and verify via known contact methods before opening attachments.

Red flags to watch for

  • PDF pushes you to a website to view the ‘real’ content
  • Website checks your location/environment before offering a download
  • Unexpected script/file download (e.g., VBS) to ‘continue’
  • Unusual attachment type for invoices (SVG)
  • Pressure to open and process quickly
  • Sender/domain doesn’t match the usual vendor records
  • Unexpected legal threat delivered by email
  • Urgent/serious tone pushing immediate action
  • Attachment/link not from an official, verifiable domain
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “Invoice attached, please review and process.” Looks normal, right? The attached PDF says, “Click here to view the full document online.” Behind that click is BraZetsu, a Windows malware toolkit used to turn your computer into "access for sale" on underground markets. The phishing PDF sends you to a fake site that scans your environment, then, if you’re in the right region, drops a VBS script and finally an EXE payload. Here’s the tell: a so-called invoice PDF or SVG that doesn’t actually show the document, but pushes you to a website, which then tries to download a script, like .VBS, to "continue." That’s not how real invoices or Edge updates work. If a PDF or invoice email sends you to a site that wants you to download or run a script or EXE, stop. Don’t open it, report the email and the file to Security immediately.

Similar attacks

“TTF Trap” Uses Fake Font Files to Drop Malware

“TTF Trap” Uses Fake Font Files to Drop Malware

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive that ultimately runs malware on Windows. The trick is a file ending in .ttf (TrueType font) that is actually a malicious script executed by…

July 17, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Hijacked .gov.br Sites Used as Malware Lures

Hijacked .gov.br Sites Used as Malware Lures

Researchers reported an active PhantomEnigma campaign where attackers hijacked 20+ Brazilian government websites and used them as trusted stepping-stones to deliver malware. The lure used official-looking police-themed documents (sometimes with QR codes) and emails that could pass common email…

July 16, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Check Point says North Korea’s Lazarus Group targeted defense and aerospace professionals using convincing fake job offers that led victims to download trojanized PDF software. The campaign used a Windows zero-day (now patched as CVE-2026-68820) to gain full control and hide from security tools,…

August 13, 2026