Netskope Threat Labs

Pidief

ATP Sandbox Adv. HeuristicsAV

Pidief is malware that exploits vulnerabilities in PDF readers to execute malicious code on vulnerable systems. It arrives through spam email attachments, and successful exploitation gives cyberattackers the privileges of the user who opened the document. Although modern readers patch the flaws the family targets, detections still surface when users open old documents or run outdated software, so the name remains a useful marker of exploit driven PDF attacks.

First seen
January 2022
Last seen
October 2026
Alert Name
Binary.Exploit.Pidief
Binary.Trojan.Pidief
ByteCode-SWF.Trojan.Pidief
Document-HTML.Exploit.Pidief
Document-PDF.Exploit.Pidief
Document-PDF.Trojan.Pidief
Document.Trojan.Pidief
Email-MIME.Trojan.Pidief
Email-MSG.Trojan.Pidief
Exploit.Pidief.K