Hackers are once again using the zero-day hole in Adobe Reader and Acrobat to install a remote-control Trojan on victim machines.
The attacks start with a malicious .pdf that the Internet Storm Center has analysed in depth. The ISC is a volunteer organisation that tracks internet attacks.
"Malicious PDF documents are not rare these days," said an ISC spokesperson, adding that attacks typically attach them to emails. But targeted attacks only sent to a small number of victims are often missed by security programs, and the attack sample sent to the ISC was initially detected by only six out of 40 antivirus vendors.
This particular attack attempts to install the PoisonIvy Trojan, which allows an attacker to gain remote control over an infected PC.
It also drops off a harmless .pdf file named baby.pdf and then opens it with Reader, a bit of digital sleight-of-hand intended to disguise the attack.
The Adobe flaw has been under attack since it was disclosed last month.
In its security bulletin, Adobe notes that for some combinations of Windows and Reader versions, this security hole will only allow for crashing Reader instead of installing malware.
Using an alternate .pdf reader such as Foxit should also help mitigate the threat.