How it works

The payload is dressed as paperwork. Inside an attached or downloaded folder is a file that looks like a document but is a shortcut or a script: brief.pdf.lnk, contract.docx.js, or details.vbs. Windows hides known file extensions by default, so brief.pdf.lnk appears as brief.pdf with a document icon. Double-clicking a .lnk runs a hidden command that quietly pulls down a stealer, and a .js or .vbs runs straight through the Windows Script Host with no visible window.

The email poses as a software brand such as Hostinger and simply says "open the brief in the folder." The double extension is the entire trick, and it works because most people never see the part after the icon.

The tell-tale signals

What to do

Turn on "show file name extensions" in File Explorer so the real ending is always visible. A brief is a .pdf, and a .pdf.lnk is not a PDF, it is a program. Do not open files inside archives that came from a cold offer. Confirm any real deal through the brand's own domain, which for Hostinger is hostinger.com. If you opened one of these files, treat the Google account as compromised and recover it from a clean device: new password, all sessions signed out, and channel access reviewed.