Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
Recent breach exposes supply chain risks via OAuth and secrets misclas...
DESILO Launches World’s First Fully Homomorphic Encryption Libra...
North Korean hackers steal more than US$12m from Web3 developers using...
Tencent Cloud Cube Sandbox Goes Fully Open-Source, with Five Major Bre...
We buckle seatbelts instinctively: why not authentication standards?
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      How AI is supercharging insider threats

      How AI is supercharging insider threats

      Wednesday, April 15, 2026, 12:29 PM Asia/Singapore | Features
    • Featured

      Q-Day is coming. Are you ready?

      Q-Day is coming. Are you ready?

      Tuesday, April 14, 2026, 12:40 PM Asia/Singapore | Features
    • Featured

      How lean defence teams turn endpoint insights into measurable risk reduction

      How lean defence teams turn endpoint insights into measurable risk reduction

      Monday, April 13, 2026, 3:15 PM Asia/Singapore | Features
  • Opinions
  • Tips
  • Whitepapers
  • Awards 2026
  • Directory
  • E-Learning

Select Page

Tips

How to outsmart filename masquerading: A practical guide to safer file handling

By L L Seow | Monday, May 26, 2025, 5:46 PM Asia/Singapore

How to outsmart filename masquerading: A practical guide to safer file handling

An age-old cybercriminal tactic has been rejuvenated, thanks to popular AI platforms that generate sought-after images and video files for download.

A recent high-profile case had involved the impersonation of a popular generative AI (GenAI) platform that has millions of users. Using fake Facebook ads and a convincing spoof of the platform’s website, cybercriminals lured victims into downloading files that appeared to be images or videos generated by the GenAI prompts.

Such sought-after output by millions of users tends to lower people’s guard. They will not notice anomalies in the filename of such output, such as unusual glyphs (“…”) or double extensions (for example, “.doc.exe”). In actuality, depending on how Windows users set their File Explorer preferences, some filename anomalies may not even be visible! However, once the supposedly harmless image (*.jpg or *.png) or video (*.mp4) files are downloaded and opened, users will have launched a malicious Windows executable.

This devious technique is called “filename masquerading”. By leveraging popular platforms that by nature are expected to generate normally harmless files for users (such as images or videos), cybercriminals can fool even savvy users into downloading and executing malware.

Understanding how filename masquerading works — and how to spot it — can help users — even those on other less-vulnerable operating systems — from being tricked by filename masquerading.

Common filename masquerading techniques
The main idea is to mask executable files, macros and automation scripts with filenames that do not readily appear to the potential victim as such. Instead, the filenames are made to escape the attention of users, made to masquerade as image or video files that are opened in trusted editing software.

Some common techniques to mask dangerous executable files as less risky files include:

  1. Double extensions
    A classic trick is naming a file something like invoice.pdf.exe. If your system hides known file extensions (the default setting in Windows), you’ll only see invoice.pdf, not realizing it’s actually an executable program.
  2. Unicode Right-to-Left Override (RLO)
    Attackers can insert special Unicode characters (such as U+202E) into filenames, causing part of the name to be displayed in reverse order. For example, “photo_high_res\u202Egnp.js” will appear as “photo_high_resj.png”, masking the true nature of the file.
  3. Invisible Unicode characters
    Characters such as the Hangul Filler (U+3164) can be used to pad a filename, pushing the real extension out of view. For instance, a file named “Generated_Image_2025.jpg[U+3164 x50].exe” can appear as just “Generated_Image_2025.jpg” in Windows.
  4. Spaces and special characters
    Adding spaces or special symbols at the end of a filename can hide the true extension or make the file look more legitimate. Use of spaces or special Unicode fillers can push the real extension out of view on certain Windows device configurations.
  5. Legitimate-looking icons and names
    Malicious files may be set to make the operating system display a certain icon — such as a standard image icon — that is familiar and safe to users.
  6. File signature spoofing
    Beyond masking risky filename extensions, cybercriminals can even copy digital signatures from legitimate files into a malware executable to make it appear to the operating system as an authentic and verified executable system file. This technique can evade system alerts or detection by any installed third-party cybersecurity software.
  7. File header masquerading
    In this case, even a malicious file’s internal structure is changed to make the executable match the profile of a harmless image file, for example. This can fool certain system processes or cybersecurity software that routinely monitor incoming files.

The MITRE ATT&CK framework has cataloged masquerading as a standard adversary tactic (T1036), with sub-techniques such as double file extension (T1036.007), RLO (T1036.002), and matching legitimate names or locations (T1036.005). Numerous real-world malware families and threat groups have used these methods, from spear-phishing attachments to advanced persistent threat campaigns.

Protective and prevention measures

Filename masquerading is a powerful tool in the cybercriminal’s arsenal, but with a little vigilance and the right settings, Windows users (and even those running the more-secure operating systems) can protect themselves and others around them.

Always set Windows file browser tools to show file extensions, be wary of suspicious files/filenames, and keep software up to date:

  • Enable file extension visibility: Make this the default setting on all Windows devices.
  • Use reliable cybersecurity software: Modern security solutions can detect many masquerading tricks. However, do not rely only on such tools alone
  • Keep your system updated: Install Windows security updates and application updates in a prompt manner, to quickly patch vulnerabilities that attackers could exploit.
  • Be skeptical: If something feels off — a very long file name, an unexpected attachment, or a download from a new website — trust your instincts and investigate before opening a file.
  • Educate others: Share this knowledge with friends, family, and colleagues. The more people know about these tricks, the less effective they become. If anything is amiss with a file, the first thing to do is to quarantine it instead of double-clicking on it. Scan it with a cybersecurity tool. Report it to the IT team. A more risky option could involve physically renaming the file to a short name with a harmless extension for the type of file it is supposed to be. If opening that supposed image file in a photo viewer app does not work, then the original filename could have been a masqueraded one.

If all protective measures fail, and a file that has been launched does not appear to be what it is supposed to be, immediate measures to take are: Disconnect from the Internet, and shut the device down immediately. Report the incident to IT without delay.

Share:

PreviousSophisticated crypto theft operation exploits phishing, smart contracts to steal millions
NextKnow the four most common password mistakes

Related Posts

Three members of notorious business-email compromise group arrested

Three members of notorious business-email compromise group arrested

Thursday, December 3, 2020

How did application security levels fare across 19 industry sectors?

How did application security levels fare across 19 industry sectors?

Friday, November 15, 2024

Vulnerability patching is hard to do: just do it anyway

Vulnerability patching is hard to do: just do it anyway

Wednesday, October 13, 2021

Earn $$$ commission daily for easy work. Click here to get your data stolen!

SMS phishing scam: Earn $$$ commission daily for easy work

Friday, May 21, 2021

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

PARTICIPATE NOW

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper
  • 2024 Insider Threat Report: Trends, Challenges, and Solutions

    2024 Insider Threat Report: Trends, Challenges, and Solutions

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper
  • AI-Powered Cyber Ops: Redefining Cloud Security for 2025

    AI-Powered Cyber Ops: Redefining Cloud Security for 2025

    The future of cybersecurity is a perfect storm: AI-driven attacks, cloud expansion, and the convergence …Download Whitepaper
  • Data Management in the Age of Cloud and AI

    Data Management in the Age of Cloud and AI

    In today’s Asia Pacific business environment, organizations are leaning on hybrid multi-cloud infrastructures and advanced …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more
  • What AI worries keep members of the Association of Certified Fraud Examiners sleepless?

    What AI worries keep members of the Association of Certified Fraud Examiners sleepless?

    This case study examines how many anti-fraud professionals reported feeling underprepared to counter rising AI-driven …Read more

Bottom sidebar

Other News

  • DESILO Launches World’s First Fully Homomorphic Encryption Library Integrating 5th-Generation FHE Scheme ‘GL’, Accelerating the Era of Private AI

    Tuesday, April 28, 2026
    SEOUL, South Korea, April 28, …Read More »
  • Tencent Cloud Cube Sandbox Goes Fully Open-Source, with Five Major Breakthroughs Enabling Large-Scale Agent Deployment

    Thursday, April 23, 2026
    Tencent Cloud’s Cube Sandbox goes …Read More »
  • Sparrow to Demonstrate AI-Driven Security and SBOM Management at Black Hat Asia 2026

    Wednesday, April 22, 2026
    SINGAPORE, April 21, 2026 /PRNewswire/ …Read More »
  • Relativity to Establish Singapore Entity, Expanding APAC Footprint

    Wednesday, April 22, 2026
    News Summary:  Relativity plans to …Read More »
  • Cohesity Appoints Nigel Lee as Technical Sales Leader, Asia Pacific and Japan (APJ)

    Wednesday, April 22, 2026
    SINGAPORE, April 21, 2026 /PRNewswire/ …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.