216.73.217.22

Tricks and Treats: New Pixel-Level Deception

· Published 18/10/2024 21:03 · Modified 21/10/2024 09:53

Export JSON

Essential information

Published
18/10/2024 21:03
Modified
21/10/2024 09:53
Tags
2024-10-18 captcha configuration extractor crc32 gdi+ ghostpulse keyboard shortcuts lumma stealer pixel-level deception png files social engineering yara rules
Related entities
9 observables, 1 intrusion sets (apt), 9 techniques (mitre), 2 malware

Description

malware has evolved to embed malicious data within pixel structures of , replacing its previous IDAT chunk technique. Recent campaigns involve tactics, tricking victims with validations that trigger malicious commands through . The malware now parses image pixels to retrieve its configuration and payload, using a hash for verification. Elastic Security has updated its and tool to detect and analyze both old and new versions. The new approach streamlines deployment to a single compromised executable with the PNG file in its resources section.

External references