Wednesday, August 19, 2026

Hackers Can Steal NTLM Credentials Through PDF Files

Hackers taking advantage of the recently disclosed Microsoft Office Exploitation that allows to include information that one document has in another document. Instead of exploiting this vulnerability attackers using this feature as an advantage to embedding remote documents inside of a PDF file and to steal NTLM Credentials.

According to Checkpoint research team, “NTLM hash leaks can also be achieved via PDF files with no user interaction or exploitation”. By using this feature attackers can inject malicious contents into the PDF and if the PDF file is opened then the target automatically start leaking data in the form of NTLM hashes.

The PDF files contain primarily of objects together with Document structure, File structure, and content streams. The dictionary contains the objects that are called as entries, the first element is the key and the second element is the value.

Also Read Creating and Analyzing a Malicious PDF File with PDF-Parser Tool

By injecting a malicious entry an attacker can entice arbitrary targets to open the crafted PDF file which then automatically leaks their NTLM hash, challenge, user, hostname and domain details” Check Point researchers published PoC explaining the vulnerability.

If the user opens the document then there is no alert on attacker’s activity and it is impossible to notice the behavior. The leaked data are transferred through SMB and the attackers can use it for various SMB relay attacks.

“Our investigation leads us to conclude that all Windows PDF-viewers are vulnerable to this security flaw and will reveal the NTLM credentials,” said checkpoint research team. The issue was disclosed to Adobe and Foxit.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Windows 11 24H2 Home and Pro Support Ends in October 2026

Microsoft has issued a 60-day reminder that the Windows...

Balonx PhaaS Steals Bank OTPs in Real Time While AI Calls and Android RAT Target Victims

Mexico’s banking sector is facing a more industrialized fraud...

659 Stripe Merchant API Keys Leaked Online, Exposing 688,000 Customer Records

A data leak published on a cybercrime data-trading forum...

Cursor 0-Day Lets Attackers Execute Malicious Code by Opening a Repository

A recently disclosed security issue in Cursor IDE exposed...

BeyondTrust Endpoint Privilege Management Flaws Enable Local Privilege Escalation

BeyondTrust has revealed two high-severity vulnerabilities in its Endpoint...

Ransom Busters Ransomware Affiliate Targets Victims With Fake Data Recovery Extortion

A threat actor calling itself “Ransom Busters” is targeting...

Related Articles

Recent News