Hacker News new | ask | show | jobs
by tomatotomato37 1181 days ago
I believe the name the program reports for those prompt can be different than the actual filename, allowing an attacker to use the name of adobe reader or some other popular PDF reader instead. If the malicious script launches the actual PDF reader with a legitimate-looking PDF after executing its payload it could be hard to detect