Analytics BIOC High

Unicode RTL Override Character

An attacker may use a special right-to-left (RTL) override character to trick users into executing malicious files that look like benign file types.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Obfuscated Files or Information (T1027)
Attacker's goals:

Trick users into executing malicious files by making their file types seem benign.

Investigative actions:

Investigate the executed process. There is no reason for benign files to contain the Unicode right-to-left override character in their name.

Test period:
N/A (single event)
Deduplication:
1 Day