typetechniqueconfidencehighcreated2026-07-12updated2026-07-12evasionsocial-engineeringmasqueraderesearch-target

social-engineering-filename-lure

Malware distributors repackage benign or malicious executables with filenames that mimic legitimate business documents — purchase orders, invoices, shipping bills, payment advices, salary slips, RFQs — to exploit the Windows "Hide extensions for known file types" default. The user sees PO-12345.pdf but the file is PO-12345.pdf.exe.

Observed Patterns

  • PO<digits>.exe — purchase-order lure
  • Invoice_<digits>.exe — invoice lure
  • Payment_Advice_<digits>.exe — banking lure
  • DHL_Shipping_<digits>.exe — logistics lure
  • SALES_ORDER.pdf.exe — double-extension masquerade
  • PAYMENT_CANCELLED_AND_RETURNED.PDF.exe — banking lure with double extension

Cross-References