{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/file-masquerading/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["stealth","file-masquerading"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThreat actors, including groups like Mustang Panda and operators of the BazarLoader malware, utilize file masquerading techniques to deceive users into executing malicious binaries. By crafting filenames with double extensions (e.g., 'document.pdf.exe'), attackers take advantage of the default Windows configuration that hides known file extensions from the user interface. This makes a malicious executable appear as a harmless document or media file. The technique is frequently used in spear-phishing campaigns to deliver payloads, such as droppers or remote access trojans (RATs). Detection engineering teams should monitor for the creation of files with mismatched or dual-extension patterns, as this is a high-fidelity indicator of social engineering and malicious intent.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful execution of these files leads to unauthorized code execution, potential establishment of persistence, and subsequent compromise of host systems. Observed campaigns targeting government, private sector, and minority groups demonstrate that this technique is a reliable vector for gaining initial access to sensitive environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy the provided Sigma rule to your SIEM/EDR to monitor for file creation events that match suspicious double-extension patterns.\u003c/li\u003e\n\u003cli\u003eImplement Group Policy settings to \u0026quot;Show file extensions\u0026quot; globally, reducing the efficacy of this masquerading technique for end-users.\u003c/li\u003e\n\u003cli\u003eConfigure endpoint security solutions to alert on or block files that use high-risk combinations like '.zip.exe' or '.rar.exe' which are explicitly designed for evasion.\u003c/li\u003e\n\u003cli\u003eUse the file_event logs to baseline common legitimate software update patterns to tune out noise and reduce false positives in highly dynamic environments.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-03T13:37:08Z","date_published":"2026-09-03T13:37:08Z","id":"https://feed.craftedsignal.io/briefs/2026-09-suspicious-double-extensions/","summary":"Adversaries frequently employ files with double extensions to bypass user skepticism and exploit Windows default settings that hide common file extensions.","title":"Detection of Suspicious Double Extension File Names","url":"https://feed.craftedsignal.io/briefs/2026-09-suspicious-double-extensions/"}],"language":"en","title":"CraftedSignal Threat Feed - File-Masquerading","version":"https://jsonfeed.org/version/1.1"}