Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteA 2022 campaign investigated by HP Wolf Security used a PDF attachment as the opening lure in a multi-step infection chain that delivered Snake Keylogger. The PDF did not simply infect a computer when viewed: it persuaded the recipient to open an embedded Word document, which then retrieved a malicious OLE object and exploited CVE-2017-11882 in Microsoft Equation Editor.
What HP found
HP Wolf Security analyst Patrick Schläpfer published the technical analysis on May 20, 2022, after HP detected the campaign in March 2022. The incident is a historical case study, not evidence that a new campaign is active in 2026 or that every PDF is malicious.
At the time, HP described PDF attachments as less commonly used to infect PCs than Office formats. Its Q1 2022 report says 45% of malware stopped by HP Wolf Security used Office formats. That figure applies only to HP Wolf Security detections during that quarter; it is not a worldwide or current malware percentage.
The infection chain, step by step
- Email delivery: The victim received a malicious PDF as an email attachment.
- User redirection: The PDF displayed a prompt designed to persuade the recipient to open another, embedded file.
- Word document launch: The prompted file was a Microsoft Word document.
- Remote retrieval: The document contacted a URL and loaded an external Object Linking and Embedding (OLE) object.
- Exploitation: The OLE object contained shellcode that exploited CVE-2017-11882, a remote-code-execution vulnerability in Microsoft Equation Editor.
- Payload delivery: HP identified the resulting malware as Snake Keylogger.
Dark Reading’s account of HP’s findings also describes embedded malicious files, remotely hosted exploits and encrypted shellcode intended to evade detection. The campaign therefore combined social engineering, document features, network retrieval and an old software vulnerability rather than relying on PDF viewing alone.
Recommended Free Tools
#1 Best Overall
Why the PDF mattered
The PDF functioned as a trusted-looking container and instruction layer. Its most important action was to convince a person to take the next step. The exploit and malware arrived later through the prompted Word document and its externally loaded OLE content.
This distinction matters. A PDF can be part of an attack without the PDF format itself being inherently dangerous. Treating every PDF as malware would overstate what this incident demonstrates; treating an unexpected attachment as harmless because it is a PDF would miss the social-engineering risk.
What CVE-2017-11882 shows about patching
CVE-2017-11882 was already more than four years old when the campaign used it. Schläpfer wrote: “The exploited vulnerability in this campaign (CVE-2017-11882) is over four years old, yet continues being used, suggesting the exploit remains effective for attackers.” That is his assessment of the observed campaign, not a measurement of today’s exposure or proof that fully patched systems remain vulnerable.
The practical lesson is to verify the current support and patch status of the software in your environment through the relevant vendor’s official guidance. Do not infer present-day exploitability from this 2022 example alone.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Rank #3
What readers and organizations should do
For individual recipients
- Be cautious with unexpected PDF attachments, especially when the document asks you to open another file or enable an action.
- Do not open a prompted embedded Word document unless you have independently confirmed the sender and expected content.
- Report suspicious messages through your organization’s normal reporting process rather than forwarding the attachment to colleagues.
For administrators
- Check patch and support status for Microsoft Office, Equation Editor components and related software using Microsoft’s current security guidance.
- Review whether email controls can quarantine or detonate suspicious attachments and inspect documents that retrieve remote content.
- Use endpoint and network telemetry to investigate unexpected document-launched connections, OLE activity and keylogger-like behavior.
- Train users that a familiar file type can still be used as a lure; the critical warning sign in this case was the request to open a second file.
HP reported that its security product isolated this campaign, but that observation is not a guarantee that any product blocks every PDF-based attack. Organizations evaluating controls should assess email attachment isolation and endpoint protection against their own software, patching and response requirements.
What this case does—and does not—establish
| Question | Supported conclusion |
|---|---|
| Can a PDF be used in a malware campaign? | Yes. In this case it served as an email lure and prompted the user to open another file. |
| Did simply viewing the PDF execute Snake Keylogger? | The reported chain required the user to open the prompted Word document; the PDF was not described as directly executing the keylogger on view. |
| Was the exploit new? | No. CVE-2017-11882 was over four years old when used in the campaign. |
| How common is PDF-delivered malware today? | The available reporting for this case does not provide a current, cross-vendor or regional prevalence statistic. |
| Does the incident prove every PDF is unsafe? | No. It documents one weaponized-PDF infection chain. |
Bottom line
The 2022 Snake Keylogger campaign demonstrates why file type alone is a poor security signal. The PDF was the lure; the user-triggered Word document, remote OLE retrieval and exploitation of CVE-2017-11882 completed the chain. Use the incident to reinforce attachment scrutiny, patch verification and layered email and endpoint controls—not to label every PDF malicious or to assume that a 2022 exploit describes current system exposure.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

