{"success":true,"data":{"id":"attachment-rtl-override-in-name","label":"Bidi override in attachment filename — invoice.exe masquerading as invoice.pdf","description":"An attachment's filename contains a Unicode bidi-control character (U+202E Right-to-Left Override or similar). The canonical attack names a file `invoice\\u202Efdp.exe` — the U+202E reverses display order of everything after it, so Gmail/Finder/Explorer render the name as `invoiceexe.pdf`. The user sees a PDF and clicks; the loader runs. Canonical malware-masquerade technique used by Emotet, TrickBot, and every APT loader campaign of the last decade. Legitimate filenames never contain bidi-control codepoints in any language — even Arabic/Hebrew filenames use letter codepoints, not format controls.","tier":"danger","category":"attachment","isThin":false}}