Skip to main content
Security & Malware MechanicsIntermediate Level 7 min readUpdated August 2024

How File Extensions Can Be Spoofed: Techniques & Detection Methods

A technical analysis of double extensions, Unicode Right-to-Left Override (RTLO) attacks, hidden extension policies, and magic-byte discrepancy detection.

David Chen✓
David ChenCISSP, GCIH
Principal Systems Security Architect
Audited September 2026
Peer-Reviewed by Dr. Alistair Vance (Ph.D., CompEng)
Executive Technical Summary

File extension spoofing is a social engineering and evasive technique where an attacker disguises an executable program, script, or hostile payload to look like an innocuous document, image, or media file. Mechanisms range from abusing default Windows "Hide extensions for known file types" settings to weaponizing Unicode Right-to-Left Override (RTLO) characters and polyglot files.

Formal Standards Definition

"Extension spoofing is the deliberate manipulation of filename string representations, directory metadata, or bidirectional text formatting to deceive human operators or naive file filters regarding the true executable nature of a binary payload."

Cited Standards:Unicode Standard Annex #9MITRE ATT&CK T1036.007
Conceptual Architecture & Flow Model
Standards Model
+-------------------------------------------------------------------------+ | COMMON EXTENSION SPOOFING VECTORS | +-------------------------------------------------------------------------+ 1. DEFAULT WINDOWS HIDDEN EXTENSION EXPLOITATION: Real Filename on Disk: "Quarterly_Report.pdf.exe" Displayed in Explorer: "Quarterly_Report.pdf" (with PDF icon!) Result upon Click: Executes .EXE binary payload! 2. UNICODE RIGHT-TO-LEFT OVERRIDE (RTLO U+202E): Underlying UTF-8 String: "Payroll_Report_[U+202E]cod.exe" Rendered Visual String: "Payroll_Report_exe.doc" (Looks like .DOC!) True Binary Format: Windows Executable (.EXE) 3. ANYFILEX DETECTION METHODOLOGY: Filename String: "invoice.pdf" │ ▼ Read Magic Bytes: 4D 5A (MZ) │ ▼ MISMATCH ALERT: Extension is ".pdf", but binary magic bytes are "MZ" (.exe)!
How the AnyFileX File Intelligence Engine Implements This

Deterministic Processing Pipeline

1Unicode Character Array Audit

Scans the filename string for invisible control characters, bidirectional override markers (U+202E RTLO), and zero-width spaces.

scanUnicodeControlCharacters(fileName)
2Double-Extension Parsing

Tokenizes filename by dot delimiters to identify dangerous multi-extension sequences (e.g. .pdf.exe, .docx.vbs).

detectDoubleExtensions(fileName)
3Magic Byte Discrepancy Evaluation

Extracts the true binary signature and cross-references against the declared extension to flag severe executable masquerades.

evaluateSignatureMismatch(detectedExt, declaredExt)

How the Unicode RTLO (U+202E) Attack Works

The Unicode Right-to-Left Override character (U+202E) was designed to support languages written from right to left, such as Arabic and Hebrew. When injected into a filename, it instructs the operating system to reverse the visual order of all subsequent characters: * Attack Filename String: `annual_summary_[U+202E]fdp.exe` * Visually Displayed String: `annual_summary_exe.pdf` To human users, the file appears to end with the safe extension `.pdf`. But to the Windows operating system kernel, the true extension remains `.exe`, causing it to execute as a program when double-clicked.
RTLO Detection in AnyFileX
The AnyFileX File Intelligence Engine automatically strips and flags bidirectional Unicode control characters (U+202A to U+202E) during file ingestion.

Configuring Windows Explorer to Always Show Extensions

By default, Windows hides file extensions for known file types, which attackers exploit by creating files named `document.pdf.exe` (which displays as `document.pdf`). To disable this vulnerability on Windows 10/11: 1. Open File Explorer. 2. Click "View" -> "Show" (or "Folder Options"). 3. Check the box "File name extensions".
  • Always enable file name extensions in Windows File Explorer.
  • Verify downloaded files with AnyFileX Magic Byte Detector before opening from untrusted senders.
AnyFileX Technical Accuracy & Scope Boundaries

Capabilities & Operational Boundaries

AnyFileX strictly distinguishes format structural analysis and cryptographic verification from dynamic runtime malware execution.

What This Analysis Verifies
  • •Detects binary-to-extension spoofing (e.g. Executable disguised as PDF or JPEG).
  • •Scans filenames for Unicode RTLO (U+202E) and double-extension obfuscation.
  • •Explains defensive OS configurations to prevent social engineering attacks.
Explicit Technical Limitations
  • •Does not modify your operating system registry settings automatically.
Malware Analysis vs Format Inspection: Extension spoofing detection identifies deception in naming and header consistency. It is a vital layer of defensive file intelligence, but should be combined with endpoint protection.
Connected AnyFileX Interactive Utilities
Magic Byte Detector

Instantly detect if a file extension is spoofed or mismatched.

Launch Tool Now
File Analyzer

Full metadata, Unicode filename audit, and header verification.

Launch Tool Now

Key Terminology & Standards Glossary

RTLO

Right-to-Left Override (Unicode character U+202E), a formatting character used to reverse the visual direction of text.

Double Extension

The tactic of naming a file with two extensions (e.g. file.pdf.exe) to trick users when extensions are hidden.

Spoofing

The act of disguising a communication or payload from an unknown source as being from a trusted source.

Related Technical Authority Guides

What Are Magic Bytes? The Binary DNA of File Formats
How File Type Detection Works: Multi-Layered Analysis Architecture
What Are Macro-Enabled Office Files? DOCM, XLSM & VBA Security

Referenced File Format Specifications

Frequently Asked Technical Questions

Can a photo or music file secretly contain a virus?

A genuine raster image (.png, .jpg) or audio file (.mp3) cannot execute code on its own. However, an attacker can disguise an executable by renaming "virus.exe" to "song.mp3.exe" or "photo.jpg", relying on users to double-click it. AnyFileX checks the magic bytes to expose this trick.