How does the disguise work?
File is foo.pdf.desktop in a zip file. zip unzipped, DE hides .desktop and shows “foo.pdf”
User double clicks thinking it’s a safe pdf but it’s actually a script or other payload which does bad things.
How does the disguise work?
File is foo.pdf.desktop in a zip file. zip unzipped, DE hides .desktop and shows “foo.pdf”
User double clicks thinking it’s a safe pdf but it’s actually a script or other payload which does bad things.