← Back to feed
PhishingEmerging1 sourceAug 10, 2026 · 14:36via Kaspersky Blog

Detection blind spots: polyglot file formats in mass mailings and targeted attacks

Brief

Files built with the polyglot technique have been showing up more and more in cyberattacks in recent years. They let attackers slip malware past email filters and file scanners, deceive victims in phishing attacks, and complicate incident investigations. To pull this off, attackers deliberately construct a file that a system can interpret as different formats depending on which application opens it.

A classic example is a file that can be handled as a PNG image or a ZIP archive. All it takes is changing the file’s extension, or simply using one or another application to open it.

Let’s take a look at why it’s even possible to create files like this, which format combinations have turned up in real-world attacks, and how organizations can protect themselves from this threat.

Why polyglot files are possible

The data formats behind polyglot files are seldom exotic.

Read more on Kaspersky Blog