typeconceptconfidencehighcreated2026-06-21updated2026-06-29social-engineeringdefense-evasionmasqueradingresearch-target

social-engineering-filename-lure

The practice of naming a malicious file with a theme that exploits the victim's professional context or urgency — invoices, payments, shipping documents, purchase orders, HR notices, IT updates — to increase the likelihood of execution. Often combined with double-extension-masquerade or version-info-masquerade to further lower suspicion.

Common Themes

  • Banking / payment proof (Proof_of_payment, Bank_Advice, Invoice)
  • Logistics / shipping (DHL, FedEx, Shipping_Documents)
  • Procurement (PO, Purchase_Order, Quotation)
  • HR / payroll (Payslip, Holiday_Notice, Contract)
  • IT / security (Update, Patch, Security_Notice)

Observed in

  • unclassified-dotnet — payment-cancelled, DHL shipping, purchase-order, and Indonesian banking-slip (Slip_Pembayaran.exe) lures. ^[/intel/analyses/b094a2b61576904f86948cebe5b0d49198f0da3b6a851574f9fede93bef28285.html]
  • unclassified-dotnet-chess-engine160820242003464366.pdf.exe — Czech chess-game lure distributing a signed .NET bitboard engine. ^[/intel/analyses/7d18d78c5cd6a14d0d70d5454d54b178860dc4b74cd0212c0f9e533368ecaf01.html]
  • brooterSALES_INQUIRY.pdf.exe — procurement-themed lure distributing a Russian Delphi brute-forcing tool. ^[/intel/analyses/b04aa5d0ede5653b20f6db6d6df0020e396dfe8688f2c4712cff6dccce2002d4.html]