Advertisement
DOUBLECUP Malware: Appended PowerShell Payloads in PNG Files
Analysis of DOUBLECUP malware reveals a deceptive technique: appending cleartext PowerShell payloads to PNG image files, bypassing traditional steganography.
North Korean Actors Use SVG Steganography to Deliver OtterCookie
North Korean threat actors are hiding OtterCookie malware in SVG flag images within fake coding tests to target developers and steal cryptocurrency.
Ghostcommit: Hidden Prompt Injection in Images Targets AI Agents
Researchers demonstrate Ghostcommit, a technique using images to hide prompt injection attacks that trick AI agents into exfiltrating repository secrets.
Microsoft Pulls 119 Malicious StegoAd Edge Extensions
Microsoft removes 119 Edge extensions linked to the StegoAd campaign, which used steganography in images and fonts to steal credentials and commit ad fraud.
MSI-Branded Image Steganography: Analysis of WeTransfer Phishing
Analysis of a recurring phishing campaign using steganography in MSI-branded images to deliver malicious payloads via WeTransfer links and bypass security.
WordPress Sites Targeted by Malware Using Steam Profile Dead-Drops
Over 2,000 WordPress sites compromised in a campaign hiding C2 resolution data within Steam Community profiles. Technical breakdown of the evasion tactics.
Advertisement
LLM Text-in-Text Steganography: Emerging Covert Channel Risks
Analysis of how Large Language Models enable sophisticated text-in-text steganography for covert communication, data exfiltration, and C2 operations.
Malware Delivery via Malicious .WAV Files — Technical Analysis
Security analysts identify .WAV audio files being used to hide malicious payloads. Learn how steganography allows attackers to bypass perimeter security.
Backdoored Telnyx PyPI Package Uses Steganography to Deliver Malware
Security researchers discovered malicious versions of the Telnyx PyPI package delivering infostealers via steganography hidden in WAV audio files.
Telnyx PyPI Package Compromised by TeamPCP via Steganography
TeamPCP threat actors distributed malicious Telnyx Python package versions 4.87.1 and 4.87.2 on PyPI to harvest credentials using hidden WAV files.