How it works
The payload is dressed as paperwork. Inside an attached or downloaded folder is a file that looks like a document but is a shortcut or a script: brief.pdf.lnk, contract.docx.js, or details.vbs. Windows hides known file extensions by default, so brief.pdf.lnk appears as brief.pdf with a document icon. Double-clicking a .lnk runs a hidden command that quietly pulls down a stealer, and a .js or .vbs runs straight through the Windows Script Host with no visible window.
The email poses as a software brand such as Hostinger and simply says "open the brief in the folder." The double extension is the entire trick, and it works because most people never see the part after the icon.
The tell-tale signals
- A file name that contains two extensions, the real one being .lnk, .js, .vbs, .wsf, .hta, .jar, or .ps1
- The "document" sits inside an archive rather than being attached on its own
- Instruction to open the specific file inside the folder
- A software brand sending from a domain it does not own
What to do
Turn on "show file name extensions" in File Explorer so the real ending is always visible. A brief is a .pdf, and a .pdf.lnk is not a PDF, it is a program. Do not open files inside archives that came from a cold offer. Confirm any real deal through the brand's own domain, which for Hostinger is hostinger.com. If you opened one of these files, treat the Google account as compromised and recover it from a clean device: new password, all sessions signed out, and channel access reviewed.