File Extensions Aren’t a Lock: How to Spot (and Stop) Disguised Downloads
That “invoice.pdf” might be an app in disguise. Learn how file extensions work, common tricks, and simple checks before you open anything.
- A filename can lie—your device decides what it is based on more than the icon and ending.
- Attackers hide behind double extensions, look‑alike names, and compressed files to slip past quick scans.
- A few habits (show extensions, preview safely, verify the source) cut most risk without being “techy.”
Why “.pdf” and “.jpg” don’t always mean what you think
Most of us treat file extensions like labels on a jar. If it says .pdf, we assume it’s a document. If it says .jpg, it’s a photo. That’s usually true—and that “usually” is exactly what scammers rely on.
A file extension is the short ending on a filename (like report.pdf or photo.jpg). It’s a hint to your computer about what app should open it. But the extension is also just text in the filename, which means it can be misleading on purpose.
Here’s a real-life scenario: you’re waiting on a delivery, and an email arrives with an attachment called ShippingLabel.pdf. You open it. Instead of a label, something installs in the background, or a login page pops up asking for your password. You didn’t “download a virus,” you just trusted a familiar-looking filename.
To keep things simple, think of extensions like a costume: they can help you recognize a file at a glance, but they’re not a security badge. Some files can wear convincing costumes, and some devices hide the costume details entirely.
- What you see: A nice icon and a filename ending (e.g., “invoice.pdf”).
- What your device uses: File type info, app associations, and sometimes the file’s internal structure.
- What attackers exploit: Quick human judgment—icons, names, urgency, and the fact that many systems hide extensions.
The goal isn’t to make you suspicious of every file forever. It’s to help you recognize the handful of tricks that show up constantly in scams, especially in email attachments, shared links, and downloads from messages.
The most common “disguised download” tricks (with examples you can recognize)
Disguised downloads are rarely clever in a technical sense—they’re clever in a human sense. They aim for that moment when you’re busy, on your phone, or trying to get something done fast.
1) Double extensions
This is the classic: a file is named to look like a document, but it ends with something else.
- Looks like:
Invoice.pdf.exe - What it is: A program (
.exe) pretending to be a PDF
On some systems, especially if file extensions are hidden, you might only see Invoice.pdf and miss the final .exe.
2) “Spaces” and long filenames that hide the real ending
Attackers use long names so the dangerous part is pushed out of view, especially in narrow columns or phone screens.
- Looks like:
2026_Tax_Return_Copy_For_Review.pdf________________.exe
If you can’t easily see the end of the filename, slow down and check the full name before opening.
3) Look‑alike letters and sneaky punctuation
Some filenames use characters that look nearly identical to common letters.
- Looks like:
pаyroll.pdf(the “a” is not the normal Latin “a”) - Or:
report.pdf(dot looks normal but is a different character)
You don’t need to become a typography detective. Just recognize the pattern: if something feels “slightly off,” treat it as a signal to verify the source.
4) Compressed files that hide what’s inside (ZIP/RAR/7Z)
A ZIP file is like a folder in a single package. Scammers use it because:
- Some email systems are less strict about scanning ZIPs than direct executables.
- It adds a step that makes people feel like it must be legitimate (“it’s just a zip”).
Example: you receive Photos.zip and inside is Photos.scr or Photos.exe. The outer file looks normal; the danger is inside.
5) “Office” files that ask you to enable something
Modern Office apps have improved safety a lot, but scams still lean on old habits:
- “Enable editing”
- “Enable content”
- “This document is protected—click to view”
Any document that needs you to enable special features to “see” the content is worth treating like a stranger asking to borrow your phone. Could be fine. Could be a problem. Verify first.
| What it looks like | Why it works | Safer move |
|---|---|---|
| “Invoice.pdf.exe” | People focus on the first extension | Check the last extension; don’t run unknown programs |
| “Document.pdf” inside a ZIP | ZIP feels routine and hides contents | Preview the ZIP’s contents; look for .exe/.scr/.bat |
| File icon looks like a PDF | Icons are easy to fake or misleading | Verify file type details; confirm sender/channel |
| Word/Excel asks to “Enable content” | Uses urgency + habit | Close it; ask for a link or resend as PDF |
A practical checklist: what to do before you open a file (email, chat, or download)
This is the part you can actually use day-to-day. You don’t need special tools—just a short routine that fits into normal life.
Step 1: Ask “Was I expecting this?” (and from this person?)
If you weren’t expecting an attachment, treat it as untrusted by default—even if it appears to come from someone you know. Accounts get hacked, and scammers impersonate coworkers, delivery services, and even friends.
Try this quick mental filter:
- Context: Does this match an ongoing conversation?
- Channel: Would your bank/HR/client really send a file like this?
- Tone: Is it urgent, vague, or pressure-y (“ASAP”, “final notice”, “last chance”)?
Step 2: Make the filename show its full ending
Many devices hide file extensions, which is like hiding the ingredients list on food. If you can, enable “show file extensions” on your computer. (The exact clicks vary by system, but the setting is common and worth doing once.)
If you can’t change settings (work computer, shared device), you can still:
- Look at the file’s Type column (on many file managers)
- Right-click → Properties / Get Info to see what it really is
Step 3: Be extra cautious with these endings
You don’t need to memorize a long list. Just recognize that these are typically “run something” formats:
.exe,.msi(Windows installers/programs).bat,.cmd(scripts).scr(screensaver files—often abused).jar(Java apps)
If someone sends you one of these and you weren’t explicitly expecting software, that’s a strong “do not open” signal.
Step 4: Prefer “view-only” paths when possible
If the file is supposedly a document:
- Ask them to send it as a PDF (still not perfect, but generally safer than a macro-enabled Office file).
- If it’s a form, ask for a secure link to a known service (company portal, official cloud drive).
- Use a preview feature (many email clients and cloud drives can preview without downloading).
Step 5: Verify using a “second channel” when stakes are real
If the file relates to money, passwords, HR, legal stuff, or anything you’d be sad to lose:
- Call the person using a known number (not the one in the email).
- Message them in a different app than the one that delivered the file.
- For companies, navigate to the official website yourself instead of clicking.
This step feels “extra”… until it saves you from wiring money to the wrong account because a fake “updated invoice” looked convincing.
Not necessarily. Icons can reflect what the system thinks should open the file (or what the file is pretending to be). The safer check is the full filename ending and the file’s type in its info/properties.
Not necessarily. Icons can reflect what the system thinks should open the file (or what the file is pretending to be). The safer check is the full filename ending and the file’s type in its info/properties.
A normal PDF is usually safer than a file that can run code, but “safer” isn’t “safe.” The biggest risk is still trusting the source. If you weren’t expecting it, verify first.
A normal PDF is usually safer than a file that can run code, but “safer” isn’t “safe.” The biggest risk is still trusting the source. If you weren’t expecting it, verify first.
People you know can accidentally forward something risky, or their accounts can be compromised. If the message feels out of character (“Hey open this”), or the attachment is unexpected, confirm with them using another channel.
People you know can accidentally forward something risky, or their accounts can be compromised. If the message feels out of character (“Hey open this”), or the attachment is unexpected, confirm with them using another channel.
One last everyday tip: if you ever feel rushed—“I should open this quickly”—that’s the moment to slow down. Disguised downloads work best when you’re multitasking, on a small screen, or trying to be helpful. A 10-second check is often the difference between “nothing happens” and a very long afternoon resetting passwords.
If you want a simple habit that fits almost any situation, use this three-part pause: expectation (was I expecting it?), ending (what does it actually end with?), and origin (can I verify the sender another way?).