A large “pump-and-dump” stock spam campaign is underway, but rather than including the content of the spam in an image file, this campaign includes the spam content within a .PDF file. The stock spam is believed to be sent from Stration infected computers, as this spam campaign closely followed a new W32/Stration worm mass-mailing which contained a number of .PDF files, and Stration has been associated with pump and dump spam in the past.

The current spam contains one or more .PDF files, has a randomly generated subject line and sender name, and a blank message body. The .PDF files contain images which look very similar to previous image based stock spam. 

PDF Image spam

The appearance of PDF-based spam was predicted by AVERT in the article “Email Spam Plague Persists” in the latest SAGE report, as .PDF files can be more easily automated than other document formats. This prediction appears to be holding true, and as .GIF based image spam continues to decline we expect spammers will continue to try similar methods of sending image based spam.