Netskope Threat Labs

PhishingX

ATP Sandbox Adv. Heuristics

PhishingX is a malicious PDF file used as part of a phishing campaign to redirect victims to a phishing page. The document carries embedded links and scripts that lead users to credential harvesting sites, bypassing defenses that focus on email attachments alone. Researchers documented the family in a RedLine stealer campaign that abused PDF links, and detections indicate exposure to credential theft lures.

First seen
February 2022
Last seen
October 2026
Phishingx
Alert Name
Document-PDF.Phishing.PhishingX
Document-PDF.Trojan.Phishingx
Document-PDF.Trojan.PhishingX
Script-JS.Phishing.PhishingX