CLIENT SIDE ATTACKS - Spoofing backdoor extension
- Change the extension of the * from exe to a suitable one.
- Make the * even more trustable.
We will use an old trick using the "right to left overload" character.
1. Open up the character map.
2. Go to find.
3. Search for U 202E.
4. Copy character.
5. Rename * an in the following format -> *[RTLO]pdf.exe