Skip to main content
← Back to Demos
Extension Mismatch beginner · 15 min

Extension-Mismatch Smuggle — ToxicPanda 2.0 & ShinyHunters Hide Loaders Behind a Benign .jpg

File-extension masquerading remains a top delivery vector even as CISA races to patch perimeter flaws — on 2026-08-25 it added CVE-2026-21962 (Oracle WebLogic, CVSS 10.0) to its KEV catalog, yet stage-2 loaders still reach endpoints through benign-looking extensions. Extortion crews such as ShinyHunters (the group that breached security vendor ReliaQuest in a 2026-08-25 disclosure) and the ToxicPanda 2.0 Android banking trojan now targeting 349 financial apps routinely ship a malicious shell script or payload under a harmless '.jpg' name: a user double-clicks 'vacation-photo.jpg' and the OS happily executes the embedded script instead of opening an image. Naive allowlists that trust the file extension (or the icon) pass the disguised loader straight through. This demo reproduces the trick safely: the malicious sample is a benign, calculator-only Bash script saved as 'malicious-photo.jpg' — if launched, it only opens a calculator, with no real payload, no network, no destruction. MetaDefender FileType Engine inspects the actual content rather than the extension, flags the declared-vs-real type mismatch, and blocks the file before execution — the same control that would neutralize extension-spoof loaders used by ShinyHunters and ToxicPanda 2.0.

Attack Technique

File-extension masquerading to hide a script as a benign image (T1036.005)

MITRE ATT&CK

T1036.005 ↗

Platforms

linux

File Types

.cmd.jpg

MetaDefender Capabilities

FileType Engine

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---