Detection blind spots: non-standard file formats in malicious email campaigns | Kaspersky official blog

Refract AI Intelligence Digest

BLUF

Threat actors are exploiting obscure file formats to evade traditional email security controls.

NEWS

Kaspersky researchers identified campaigns using disk images, polyglots, and atypical Office files to deliver malware covertly. These techniques bypass signature-based detection by mimicking benign data structures. Real-world attacks confirm this trend is active and evolving.

Why I Care

Standard email gateways often ignore or fail to scan these formats deeply, leaving enterprises vulnerable to initial access breaches. This impacts all organizations relying on email for communication and file exchange.

Next Steps

Security teams should update email filtering rules to inspect non-standard attachments immediately. Conduct a review of current DLP and sandboxing policies by the end of the quarter to ensure coverage of vector graphics and disk images.

Disk images, atypical Office files, vector graphics, polyglots, and other techniques for covertly launching malware, as seen in real-world cyberattacks.
Back to Blog Listing

Source: Kaspersky Security Blog ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.