CYBER WELFARE

Protect your Digital Privacy

Malware in email attachments: how the tricks that travel inside a file actually work

An invoice you were expecting, a delivery notice, a document shared by a colleague. Attachments are part of everyday life, and that is exactly why they are one of the most common ways of getting a harmful program onto a device.

Malware in email attachments means this: a file that looks like an ordinary document but contains, or leads you to download, malware, meaning software designed to spy on you, steal data, lock your files or take control of your device. The techniques used to hide it change over time, but they have more in common than it might seem.

This post describes the most common ones, one by one. It is the threat-side companion to the recommendation on not opening unknown attachments: an unexpected attachment stays closed until you know who sent it and why, and when in doubt, you delete it.

One useful clarification: this post describes how these attacks work from the point of view of the person on the receiving end, so that you can recognise them and defend against them. It contains no operational instructions.

The starting point

It is Thursday morning and you are waiting for a parcel. An email arrives from a courier: “Delivery failed, please fill in the attached form.” The attachment is a compressed archive, and the message also gives you the password to open it, “to protect your data”.

A little later, an invoice arrives as a PDF. There is almost nothing inside, just a QR code: “Scan to view the payment details.”

In the afternoon, a colleague replies to an old conversation: “Here is the updated document.” The file opens blank and asks you to “enable content”.

None of the three messages is what it seems. They are three different techniques with one goal in common: getting you to take one more step.

Why attachments work as bait

All the techniques that follow share one thing: they do not need to break through your device’s defences, they only need to persuade you to open the file and make one move: enable some content, type a password, scan a code, sign in to “view” a document. To get there, they rely on three levers:

  • expectation: invoices, parcels and work documents are things we genuinely wait for;
  • trust in the format: a document feels like a page to read, not a program that does something;
  • getting past the filters: many of these tricks exist to hide the content from the automatic checks your email service runs.

None of these levers requires extraordinary skills. The message goes out to a very large number of people, and it only takes a few to open it at the wrong moment.

1. The document with macros

In plain terms. A document or spreadsheet that, in order to display itself, asks you to turn on macros: small programs built into the file to automate tasks.

How it works. The file opens, but the content looks blurred, blank or “protected”. A notice invites you to “enable content” to see it properly. That click shows you nothing useful: it starts the hidden program, which often downloads further harmful software from the internet.

Why it works. Macros have legitimate uses in work forms, and the notice looks like a routine technical step. Many office programs now block macros in files that come from the internet, which is exactly why attackers put so much effort into asking you to unblock them.

Possible impact. Theft of passwords and data saved in your browser, remote access to your computer and, in the most serious cases, files encrypted with a ransom demand: the mechanism is described in the post on ransomware and personal files.

What should make you suspicious. An unexpected document that shows nothing until you enable something; instructions, inside the file itself, on how to turn on macros.

How to protect yourself. Do not enable macros or active content in documents received by email, unless you know for certain who prepared them and why. An ordinary document can be read without unlocking anything.

2. The fake invoice and the fake delivery notice

In plain terms. An attachment presented as something you are expecting: an invoice, a receipt, a courier notification, a payment reminder.

How it works. The text is short and plausible, with a bureaucratic tone and a file name full of numbers and dates. The real content depends on the technique used: macros, an archive, a link or a QR code. The invoice is just the wrapping.

Why it works. Invoices and deliveries are frequent, and nobody likes to ignore a payment or miss a parcel. People who work in accounts or administration open many of them every day: it is part of the job.

Possible impact. Whatever the hidden content does; in a work setting, the office network and customer data can be affected too.

What should make you suspicious. Suppliers or couriers you have no dealings with, amounts you do not recognise, parcels you never sent, a tone that rushes you (“by today”, “final notice”).

How to protect yourself. Check invoices and deliveries through the supplier’s customer area or the courier’s website, reached by you rather than through the message. The same principle applies to emails pretending to be your bank.

3. The password-protected compressed archive

In plain terms. A compressed archive is a file that contains other files, “packed” to take up less space. If it is protected by a password, email checks cannot look inside it.

How it works. The email contains the archive and, in the text, the password, with a reassuring justification: “for your privacy”. The password does not protect you: it stops automatic filters from examining the content.

Why it works. The word “protected” sounds like a guarantee, and in some professional settings encrypted archives are genuinely used.

Possible impact. The archive can hold any harmful file, from a program that steals sign-in details to one that encrypts your documents.

What should make you suspicious. A protected archive that arrives without warning, with the password in the same email; an archive containing a single file.

How to protect yourself. Treat an unexpected password-protected archive as a warning sign in itself. Anyone who genuinely needs to send you protected files will usually agree it with you first and give you the password through another channel.

4. The double extension and the misleading icon

In plain terms. The extension is the last part of a file name, after the dot: it tells the system what kind of file it is and what to open it with. If the real extension is hidden, a program can pass for a document.

How it works. The name contains two extensions: one that suggests a document and another, at the very end, that belongs to a program. If the system does not show extensions, you only see the first one. Add an icon copied from the one used for PDFs, and the disguise is complete. At other times the file is a shortcut, which runs a command instead of opening a document.

Why it works. We recognise files by their icon and name, not by their type. And many devices hide the most common extensions by default.

Possible impact. A harmful program launched directly with a double click, sometimes without any further warning.

What should make you suspicious. Names with two dots, very long names or names padded with spaces, a “document” that shows nothing or asks for permissions.

How to protect yourself. Make file extensions visible in your computer’s settings: a choice you make once and that stays in place.

5. The attachment that is only a link to a file in the cloud

In plain terms. There is no real file in the message, only a preview pointing to a document shared on a cloud storage service (space on remote servers where files are kept and shared).

How it works. Clicking takes you to a page that asks for your email address and password “to view the document”: it is a fake page that collects sign-in details. In other cases the link genuinely leads to a well-known sharing service, from which a harmful file is downloaded.

Why it works. Sharing services are used every day, and filters tend to treat them as trustworthy. Without an actual attached file, checking the content is harder.

Possible impact. Theft of your email or work account password, and from there access to documents and contacts.

What should make you suspicious. A request to sign in to see a document; an “attachment” that shows a web address when you hover over it; shares from people you do not know.

How to protect yourself. Do not enter sign-in details on a page opened from a message: a document that has really been shared with you will be there when you open the service from its own address. A password manager (an app that stores and fills in your passwords) helps too, because it will not fill in your details on a site other than the one it has saved.

6. The QR code inside the PDF

In plain terms. The document contains no clickable links and no programs, only a QR code to scan with your phone. This variant is called quishing, from QR and phishing.

How it works. A PDF imitating an invoice or a signature request invites you to scan the code. The QR code leads to a fake sign-in or payment page. The link sits inside an image, and many filters cannot read it.

Why it works. It moves the attack from the computer, which is often better protected, to the phone, where the page address is barely visible. And scanning a QR code feels like a neutral gesture.

Possible impact. Sign-in or card details handed over from your phone; sometimes, apps installed from unofficial sources. The post on spotting the signs of malware on your phone helps you know what to look for afterwards.

What should make you suspicious. A document whose only useful content is a QR code; an invitation to scan it “for security”; a page that asks for passwords or payment straight away.

How to protect yourself. Treat a QR code in an attachment like a link from a stranger. For payments and sign-ins, use the official website or app.

7. The attachment from a known person’s compromised account

In plain terms. The email really does come from the address of a colleague, a friend or a supplier, but that account has been compromised: someone else has got into it without permission.

How it works. Whoever controls the mailbox replies to an ongoing conversation, with the same subject line and the history of previous messages. The attachment arrives as a natural follow-up: “here is the updated version”. At other times, a message goes out to the whole address book.

Why it works. The checks we usually make, sender, tone and context, all come back positive. It catches out even careful people.

Possible impact. The same as any harmful attachment, plus a chain reaction: whoever opens the file can become the sender of the next message. What happens when it is your own account writing to others is explained in the recommendation on messages sent in your name.

What should make you suspicious. An attachment nobody mentioned beforehand, a message that is more generic than usual, an old conversation that suddenly comes back to life.

How to protect yourself. When in doubt, check with the person through another channel, without replying to that email. It is a question nobody will take offence at.

Summary table

TechniqueMain riskWhat should make you suspiciousEffective defences
Document with macrosHidden program started with one clickBlurred or blank content, invitation to enableNot enabling macros in files you receive
Fake invoice or delivery noticeA file opened out of haste or habitUnknown suppliers, amounts or parcels that do not add upChecking through the customer area or official website
Password-protected archiveA file that gets past filters uncheckedPassword in the same email, unexpected archiveTreating it as a warning sign, asking for confirmation
Double extension and fake iconA program mistaken for a documentTwo extensions, long names, an icon that does not fitExtensions always visible
Link to a file in the cloudPassword handed to a fake pageRequest to sign in to “view” the fileOpening the service from its own address
QR code inside a PDFAttack moved onto the phoneA document containing only a QR codeNot scanning QR codes received in attachments
Known person’s compromised accountTrust exploited, chain reactionUnannounced attachment, old conversation reopenedConfirmation through another channel

What they have in common

Seven different techniques, three defences that cut across almost all of them:

  1. Asking whether the attachment was expected — knowing the sender is not enough: what matters is knowing why they are sending you that file, now.
  2. Not taking the extra step — enabling, typing a password, scanning, signing in: an ordinary document can be read without any of these.
  3. Checking through another channel — a phone call or a separate message takes apart the fake invoice, the fake courier and the compromised account.

On top of these comes a foundation that keeps working even when you are distracted: keeping your software up to date, which closes the security holes that some files exploit. The details to look for in a suspicious file are gathered in the guide to the signs of a dangerous attachment.

Protection checklist

  • ☐ Unexpected attachments stay closed until I know who sent them and why
  • ☐ I do not enable macros or active content in documents received by email
  • ☐ I treat an archive with the password in the message as a warning sign
  • ☐ File extensions are visible on my computer
  • ☐ I do not type passwords into pages opened from a “shared document”
  • ☐ I do not scan QR codes contained in attachments
  • ☐ I check through another channel when someone I know sends an unexpected file
  • ☐ My operating system, programs and apps are kept up to date
  • ☐ When in doubt, I delete the attachment without opening it

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessUnderstanding that a harmful attachment does not force its way into your device, but asks the person receiving it to take one more step
SkillsRecognising the mechanism of each technique from its signals, including files that come from people you know
Secure BehaviourPausing in front of an unexpected attachment and checking through another channel before opening, enabling or scanning

Reference level: FL3 — Autonomous, with a foundation also accessible from FL2 — Beginner in the sections on fake invoices and protected archives.

Conclusion

The techniques described here are rarely aimed at you in particular. They start from lists of addresses and messages sent out in large numbers, and they succeed when a file reaches someone who was expecting it, or someone in a hurry.

That is why the most effective defence is a habit rather than a tool: an unexpected attachment is opened only when you know who sent it and why, and no genuine document needs you to unlock anything in order to be read. Email filters help a great deal, and the post on how attachment scanning works explains what they can stop and what they cannot. The last step, though, is still yours.

If you have already opened a file and are now having doubts, the guide on what to do after opening a suspicious attachment sets out the steps in the right order. To work out where to start, the digital resilience self-assessment helps you take stock.

Something to think about. The last attachment you opened: could you say why it was sent to you in particular, at that particular moment?

Related resources

Short pieces from the Resources section, for anyone who wants to focus on a single aspect:

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.