A sophisticated attack campaign using steganographic techniques to hide malicious code within ordinary JPEG image files, delivering a fully undetectable (FUD) ransomware payload that bypasses traditional security solutions. In a recent campaign documented in March 2025, researchers identified attackers using this technique to distribute various RAT (Remote Access Trojan) malware, including LimeRAT, AgentTesla, and Remcos, followed by the deployment of ransomware. Once downloaded, the concealed PowerShell script activates, extracting the hidden code and establishing a connection to command-and-control servers before deploying the ransomware payload. As attackers continue to refine their techniques, organizations must remain vigilant against these increasingly sophisticated threats that turn ordinary images into vectors for devastating ransomware attacks. Hidden within the EXIF data of these images is obfuscated PowerShell code designed to initiate the attack sequence.
This Cyber News was published on cybersecuritynews.com. Publication date: Mon, 12 May 2025 12:20:05 +0000