Executable Renamed to .jpg Bypasses Naive Filters
Threat actors routinely rename executables with innocuous extensions — .jpg, .png, .pdf — to smuggle payloads past email gateways and web filters that only check file extensions. A renamed binary remains fully executable: the extension is cosmetic, while the file's magic bytes and internal structure still identify it as a Windows PE program. This mismatch is invisible to users browsing attachments and to any scanner that trusts the filename, yet it is trivial to catch by inspecting actual content. This demo uses a benign executable simply renamed to .jpg; no malware is involved. The FileType Engine ignores the filename, inspects the file's signature and structure, and flags the true format, so the mismatch is surfaced immediately and the disguised executable can be blocked or quarantined at the perimeter.
Attack Technique
Extension mismatch
MITRE ATT&CK
T1036.001 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗