Tech
Kaspersky warns of hidden malware in exotic file formats used in email attacks
Photo: stan kaminsky

Kaspersky warns of hidden malware in exotic file formats used in email attacks

Cybercriminals are increasingly using uncommon file types such as disk images, atypical Office add‑ins and vector graphics to slip malware past traditional email scanners, according to Kaspersky research.

Kaspersky’s research team has identified a growing trend where threat actors embed malicious code in file formats that are rarely inspected by conventional security solutions. The study highlights a range of "exotic" containers – from ISO disk images and XLL Excel add‑ins to SVG vector graphics and polyglot files that masquerade as legitimate documents. By exploiting the fact that many anti‑virus engines focus on well‑known extensions like .exe, .docx or .pdf, attackers can deliver payloads that remain invisible until the user opens the attachment or the file is mounted on a system.

Real‑world campaigns cited by Kaspersky illustrate the danger. In one case, a phishing email carried an ISO image that, when mounted, automatically launched a ransomware dropper hidden in the disc’s hidden folder. Another operation used a malicious XLL file – an Excel add‑in – to execute PowerShell commands that downloaded a banking trojan. SVG files, which are normally used for scalable graphics, were weaponised with embedded JavaScript that triggered drive‑by downloads when rendered in a webmail client. The most sophisticated examples involved polyglot files that behaved simultaneously as a PDF and a Windows executable, confusing signature‑based scanners that only parsed one format. These techniques expose a blind spot in many corporate email gateways and endpoint protection products that do not fully unpack or analyse the inner structure of such containers.

ALSO READ | Apple’s First Foldable iPhone Duo Set for Tonight’s Launch with Leaked Color Lineup and Pricing

Kaspersky advises security vendors to broaden their inspection capabilities to include these less common formats and to adopt behavior‑based detection that watches for suspicious actions regardless of file type. The firm also recommends regular updates to signature databases, sandboxing of attachments, and user awareness training to discourage opening unexpected files, especially from unknown senders.

Why This Matters

Email remains the most prevalent entry point for malware, and the emergence of exotic file formats erodes the effectiveness of legacy defenses that rely on static signatures. When malicious payloads bypass initial scans, they can gain a foothold in corporate networks, leading to data theft, ransomware encryption or lateral movement across systems. For organisations, this translates into higher remediation costs, potential regulatory penalties and damage to reputation. The findings underscore the need for security teams to adopt more holistic, context‑aware scanning solutions and to keep pace with attackers’ evolving tactics. By recognising and mitigating these blind spots, enterprises can close a critical gap in their cyber‑defence posture before the next wave of sophisticated email‑borne attacks strikes.

Reporting based on verified dispatches from Kaspersky. View primary release ↗
Stay Connected
Follow SamacharDaily on Instagram

Visual explainers, infographics, and daily news briefings on your feed.

More in Tech