Zimperium, the world pioneer in mobile security, has uncovered an advanced mishing (mobile-targeted phishing) campaign impersonating the United States Postal Service (USPS), exclusively targeting mobile devices.

Spearheaded by Zimperium’s zLabs threat research team, the investigation reveals an unprecedented method of obfuscation used to deliver malicious PDF files designed to steal credentials and compromise sensitive data. 

Risk of data breach

The campaign exploits the trust that users place in official-looking communications and the PDF format. Cybercriminals embed malicious elements into PDFs, using social engineering tactics to deceive recipients.

On mobile devices, where users may have limited visibility into file contents before opening them, the risks of data breaches, credential theft, and workflow disruptions significantly increase.

Method of obfuscation

Although USPS has no involvement, cybercriminals exploit its trusted name to mislead and target users,” said Nico Chiaraviglio, zLabs Chief Scientist at Zimperium.

This campaign shows the growing sophistication and continued rise of missing attacks, emphasizing the need for proactive mobile security measures.”

Key findings

  • Campaign Scale: Over 20 malicious PDF files and 630 phishing pages were identified, targeting organizations in 50+ countries.
  • Innovative Evasion Techniques: Newly discovered methods obscure malicious links, evading traditional endpoint security solutions.
  • Critical Vulnerability: PDFs used as a vector exploit mobile users’ confidence in the format, posing a significant threat to enterprise security.

Tips to verify the message's authenticity

To protect against SMS and PDF phishing attempts like this, follow these best practices:

  • Scrutinize Sender Details: Verify the sender’s phone number or email address. Official USPS messages will come from a verified source.
  • Avoid Clicking on Links: Navigate directly to the official USPS website or use their mobile app instead of clicking on embedded links.
  • Inspect PDF Metadata: On a desktop or through a trusted app, review the document properties for unusual or mismatched information.
  • Enable Security Tools: Use advanced mobile threat defense solutions to detect and block phishing attempts.
  • Report Suspicious Activity: If the user receive a questionable message claiming to be from USPS, report it at the official USPS phishing page or directly through their support channels.

In case you missed it

Enhancing Security At Lincoln's Inn With KeyWatcher
Enhancing Security At Lincoln's Inn With KeyWatcher

The Honourable Society of Lincoln’s Inn is one of the four Inns of Court and operates as an active and thriving society of lawyers, sprawling across 11 acres in central Londo...

How Are New Technologies Reshaping Casino Surveillance And Security?
How Are New Technologies Reshaping Casino Surveillance And Security?

Casinos are tasked with monitoring vast gaming floors, cashier cages, and access points. The market for casino security and surveillance demands software and hardware that provide...

ASSA ABLOY Showcases At GSX 2026 In Atlanta
ASSA ABLOY Showcases At GSX 2026 In Atlanta

ASSA ABLOY will be exhibiting at Global Security Exchange (GSX) 2026 from September 14 - 16 at the Georgia World Congress Center in Atlanta, Georgia. The company invites attendees...