Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Dangerous email attachments: the files you should never open | Kaspersky official blog

0
Low
Published: 08/07/2026 (08/07/2026, 09:57:50 UTC)
Source: Kaspersky Security Blog

Description

Have you ever tried to open an “encrypted” email or an urgent document, only to realize with horror that your usual DOCX attachment is actually a file with the extension .docx.exe? Or maybe you received an email supposedly with an invoice, contract, or internal memo attached — only for the file to prove something entirely different from what it claimed to be? If so, you were likely targeted in a malware infection attempt. Cybercriminals routinely disguise malicious files as harmless documents and archives, banking on recipients blindly clicking without checking the extension. Kaspersky experts analyzed the file formats most frequently deployed in malicious email blasts to reveal what really lurks behind these extensions — and how attackers weaponize them in their campaigns. Important note: the extensions we’ll be discussing here are routinely used for completely legitimate files. For example, Windows executables normally end in .exe. However, we’re focusing specifically on scenarios where attackers disguise or spoof a file’s extension to pass it off as a totally different type of file. What extensions are most commonly found in malware? Our experts analyzed malicious email blasts from the beginning of 2026 to pinpoint the 15 most common dangerous file extensions. .exe .js .html .dll .bat .vbs .xls .pdf .jse .au3 .docx .htm .wsf .scr .lnk The top 15 file extensions used in malicious email blasts Let’s take a look at what files with these extensions actually do under the hood. Executable files An executable file is a compiled computer program that’s ready to run. Once launched, a malicious executable can download additional payloads, alter system settings, steal user data, connect your device to external attacker-controlled servers, and much more. These are the most common executable extensions found in malicious email campaigns: .exe .dll .com .scr .exe The classic Windows executable extension. It powers every program you use daily, from web browsers and games to office suites and software installers. By the way, attackers often wrap EXE malware in double extensions: invoice.docx.exe, report.pdf.exe, or even photo.jpg.exe. They take advantage of a default Windows setting: hiding extensions for known file types. Because this setting is turned on by default, users only see the first part of the file name — invoice.docx, report.pdf, or photo.jpg — and assume it’s just a normal document or image. But the second you open this trap file, the malware fires up. .dll Another common extension abused in malicious campaigns is .dll (dynamic-link library). These libraries hold functions that Windows programs frequently require while running, such as printing a document. This modular architecture prevents redundant code by letting multiple applications call on the exact same library for specific tasks. However, if an attacker replaces a legitimate library with an infected one, running any normal program that calls on it can trigger malicious code. .com While files with the .com extension have absolutely nothing to do with the web domain of the same name, cybercriminals likely count on victims mistaking these files for links in an unusual format. In reality, it’s a legacy Windows executable format. While modern versions of Windows no longer rely on this file type, the operating system can still run and execute it, which makes opening one a very bad idea. .scr SCR files are screensavers — those idle Windows screen animations featuring abstract patterns, the iconic bouncing logo, or whatever else. Despite their harmless reputation, screensavers are essentially executables just like EXE files: once opened, they can install extra components or alter system settings all the same. In malicious campaigns, these files routinely masquerade as images, screenshots, or documents. Scripts Scripts are text files containing a sequence of commands that a computer runs automatically in order. They can download files, install and launch programs, modify securi…

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/07/2026, 10:06:19 UTC

Technical Analysis

Cybercriminals commonly use deceptive file extensions in email attachments to deliver malware. Executable files such as .exe, .dll, .com, and .scr are frequently employed, often with double extensions to appear as benign documents or images. Scripts with extensions like .js, .vbs, and .bat are also used to automate malicious actions. These files, once executed, can perform a range of harmful activities including installing malware, modifying system configurations, and exfiltrating data. The default Windows behavior of hiding known file extensions facilitates this deception. The analysis is based on Kaspersky's examination of malicious email campaigns from early 2026, identifying the top 15 dangerous file extensions used in attacks.

Potential Impact

Opening these disguised malicious attachments can lead to malware infection, which may result in unauthorized system changes, data theft, installation of additional malicious payloads, and potential compromise of the affected device. The impact depends on the specific malware delivered but generally includes significant security risks to the user and their environment.

Defensive Guidance

Users should be cautious when opening email attachments, especially those with double extensions or unexpected file types. It is recommended to disable the Windows setting that hides known file extensions to better identify suspicious files. Employing updated antivirus solutions and email filtering can help detect and block malicious attachments. No official patch or fix applies to this threat as it exploits user behavior and default OS settings rather than a software vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.kaspersky.com/blog/dangerous-extensions-in-email/56238/","fetched":true,"fetchedAt":"2026-08-07T10:06:11.289Z","wordCount":2513}

Threat ID: 6a75ae13bf8831d5391f781e

Added to database: 08/07/2026, 10:06:11 UTC

Last enriched: 08/07/2026, 10:06:19 UTC

Last updated: 08/07/2026, 18:02:56 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses