RLO Filename Spoofing Masquerades Executable as Text
The right-to-left override (U+202E) character lets an attacker craft a filename that displays as a harmless text document while the real executable extension sits at the end. A file named invoicetxt.sh is shown by file managers as invoicesh.txt, hiding the shell-script nature from users. This demo ships a real shell script with the RLO-spoofed filename and a clean counterpart. FileType Engine verifies the true magic bytes behind the displayed name, so the masquerade is exposed regardless of what the file manager renders.
Attack Technique
Right-to-left override (RLO) filename spoofing
MITRE ATT&CK
T1036.002 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗