Skip to main content
← Back to Demos
Extension Mismatch intermediate · 15 min

RLO Filename Spoofing Masquerades Executable as Text

The right-to-left override (U+202E) character lets an attacker craft a filename that displays as a harmless text document while the real executable extension sits at the end. A file named invoice‮txt.sh is shown by file managers as invoice‮sh.txt, hiding the shell-script nature from users. This demo ships a real shell script with the RLO-spoofed filename and a clean counterpart. FileType Engine verifies the true magic bytes behind the displayed name, so the masquerade is exposed regardless of what the file manager renders.

Attack Technique

Right-to-left override (RLO) filename spoofing

MITRE ATT&CK

T1036.002 ↗

Platforms

linuxmacoswindows

File Types

.sh

MetaDefender Capabilities

FileType Engine

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---