SolarMarker makers are using SEO poisoning, stuffing thousands of PDFs with tens of thousands of pages full of SEO keywords & links to redirect to the malware. They re stuffing PDF documents with SEO keywords and links that start a chain of redirects that eventually leads to the malicious malware. Microsoft Security Intelligence has seen the attackers shift from originally using Google Sites to now primarily using Amazon Web Services (AWS) and the Strikingly free website builder service. Microsoft: Microsoft Defender Antivirus has detected and blocked thousands of these PDF documents in numerous environments
Source: https://threatpost.com/rotten-pdfs-flood-web-password-snarfing/166932/

