PDF trapped that steals M365 session/account password


Recommended Posts

Hello,

Someone that i know i received a mail on Outlook 2021 (on Win 11 25H2 with the patch tuesday ot 14th october installed) which contains a PDF trapped she thought it was legitimate and she has opened the PDF. Just after she has noticied that there was a huge amount of spam send which is mail address. By opening the PDF the hacker has stolen his password of sessions/ M365 account (it's the same password for the windows sessions and his M365 account). The hacked has set a rule to move automatically the mails arriving in the inbox to a specific folder. 

How is-it possible to stole the password just by opening the PDF ?

Thanks by adance

  • Like 1
On 09/11/2025 at 02:05, xillibit said:

Hello,

Someone that i know i received a mail on Outlook 2021 (on Win 11 25H2 with the patch tuesday ot 14th october installed) which contains a PDF trapped she thought it was legitimate and she has opened the PDF. Just after she has noticied that there was a huge amount of spam send which is mail address. By opening the PDF the hacker has stolen his password of sessions/ M365 account (it's the same password for the windows sessions and his M365 account). The hacked has set a rule to move automatically the mails arriving in the inbox to a specific folder. 

How is-it possible to stole the password just by opening the PDF ?

Thanks by adance

It isn’t. I’ve seen and investigated this phishing attempt dozens of times. They open it, it triggers a prompt to login (usually via SSO), and they do. It’s all over after that. If they don’t login, they don’t get their account stolen. 
 

More importantly though, DO NOT OPEN SUSPICIOUS FILES. 

On 09/11/2025 at 09:05, xillibit said:

Hello,

Someone that i know i received a mail on Outlook 2021 (on Win 11 25H2 with the patch tuesday ot 14th october installed) which contains a PDF trapped she thought it was legitimate and she has opened the PDF. Just after she has noticied that there was a huge amount of spam send which is mail address. By opening the PDF the hacker has stolen his password of sessions/ M365 account (it's the same password for the windows sessions and his M365 account). The hacked has set a rule to move automatically the mails arriving in the inbox to a specific folder. 

How is-it possible to stole the password just by opening the PDF ?

Thanks by adance

There is a missing part of the story. 

If she in fact didn't enter her credentials, then it sounds like it stole her sessions cookies.

Didn't the same thing happen to Linus Tech tips?

Per the Verge

Quote

According to Sebastian, someone on the Linus Media Group’s team downloaded “what appeared to be a sponsorship offer from a potential partner” and launched the included PDF with the terms of that offer. But Sebastian says this offer actually included malware that accessed “all user data from both their installed browsers” — including session tokens — which effectively gave the bad actor “an exact copy” of the browsers that they could export and use to wreak havoc without needing to enter security credentials.

Are we even sure what she was trying to open was a PDF or an executable? 

 

  • Like 2
On 09/11/2025 at 11:47, adrynalyne said:

It isn’t. I’ve seen and investigated this phishing attempt dozens of times. They open it, it triggers a prompt to login (usually via SSO), and they do. It’s all over after that. If they don’t login, they don’t get their account stolen. 
 

More importantly though, DO NOT OPEN SUSPICIOUS FILES. 

@Warwagon sounds like he's on the right track, given what we know. It's called "cookie hijacking" or "session hijacking".  Malicious PDFs, or sometimes, .exe files disguised as PDFs, since Windows hides file extensions by default, have been used in the past to steal locally stored session cookies for already signed-in accounts without requiring any manual login activity or further interaction from the target user.  If this is what has happened to the OP and they still have access to the account; invalidating all currently logged in sessions, then logging back in and changing your password should be enough to boot the hackers from your account.  The longer you leave them with access however, the more likely it is they either already have, or will eventually do something like change the password the something of their choosing, remove 2FA authenticators or otherwise take greater ownership of the account.

Linus of "Linus Tech Tips" was a victim of this a couple of years ago.

 

  • Like 2
On 10/11/2025 at 10:55, xillibit said:

It can't be an executable because the extensions of files are set to showed

It doesn’t matter at this point. Either login consent was given or session cookies were stolen. You have two very plausible explanations. 
 

At the end of the day, never open suspicious files or unexpected attachments. 

  • Like 3

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I have disabled it, but the app is still taking space. I have a Mac and it is only possible to disable Ai on that, but I think that bit does get rid of the AI components after a while. What we are told is that we agree to all this when we use the devices as it is in the end user agreements, their software, they can do what they like. I doubt that any bill will happen in the U.S, the government there are in league with big tech firms. The E.U maybe, they seem to have some guts when it comes to tech companies. The U.K is not in the E.U, but some things still affect us. Our government is as gutless when it comes to tech companies as the U.s government.
    • WebChangeMonitor 26.06 by Razvan Serea Monitors allows you to quickly check a number of web pages and tracks changes based on the content of the web pages. Allows to monitor several protocols, including HTTP and HTTPS. Allows to view and record differences. Available for Win7/10, Linux and others. WebChangeMonitor features: Allows monitoring of web pages and informs about content changes Indication of states of currently monitored items in the tool and taskbar Reporting as sound and/or email as well as log file or HTML log Several configuration / filter options Support all protocols, e.g. http, https Multi-threaded, running in the background Bulk-import and bulk-export of items (from/to CSV) to monitor Export of results to CSV file for further processing Allows running command on items states and/or showing diff (changes) of content with preferred diff-tool ...and many more! Open Source (C++, wxWidgets) Cross platform for Windows (7/10), Linux, RPi and Mac (if self-compiled) WebChangeMonitor 26.06 release notes: Release 26.06 brings mostly s but updates the underlying core infrastructure. A major compiler is used for both x86/x64 and WoA64 architectures. This also means that all core libraries are re-compiled accordingly which required some changes in the build scripts. One of the core libraries (cURL) has been updated to address vulnerabilities and a nasty linker error that was causing the need for a dedicated patch which could now be eliminated. Download: WebChangeMonitor 64-bit | Setup 64-bit | ~10.0 MB (Open Source) Download: WebChangeMonitor 32-bit | Setup 32-bit View: WebChangeMonitor Website | Other Operating Systems | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • BATorrent 3.0.4 is out.
    • yea they change their app to high-system app so you can't disable with adb or within android, you gotta get root be able to do disable this high-system app now if you have locked down boot loader you screwed. samsung started locking down their store and their account app extremely annoying, account constantly nagging you to sign in... i disable all ai core apps and especially gemini since you can't uninstall anymore. i hope some day someone will present a bill force this companies quit locking down this damn phone especially the apps...
  • Recent Achievements

    • Dedicated
      Mark Spruce earned a badge
      Dedicated
    • Collaborator
      conkir earned a badge
      Collaborator
    • Rising Star
      olavinto went up a rank
      Rising Star
    • One Month Later
      lamborghiniv10 earned a badge
      One Month Later
    • Week One Done
      lamborghiniv10 earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      482
    2. 2
      PsYcHoKiLLa
      257
    3. 3
      Steven P.
      74
    4. 4
      +Edouard
      69
    5. 5
      Skyfrog
      68
  • Tell a friend

    Love Neowin? Tell a friend!