Polyglot File Valid as Both PDF and EXE
Polyglot files are crafted to parse as two different formats at once, allowing a single binary to slip past security tools that only inspect one file type. In this demo, an executable is built so it is simultaneously a valid PDF document and a valid Windows PE executable — a dual-format technique attackers use to smuggle payloads past email filters and download portals. The FileType Engine ignores file extensions and header heuristics that attackers can easily spoof, instead fingerprinting the file's actual content and reporting every format it genuinely matches. When the polyglot is submitted, the engine flags both the PDF and EXE interpretations, giving security teams the full attack surface before any processing decision is made.
Attack Technique
Polyglot PDF/EXE
MITRE ATT&CK
T1036.005 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗