Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines

Summary

A new malware campaign, dubbed "ClickFix," employs a multi-stage attack chain that conceals malicious code within PNG image files. Once executed, the malware establishes a custom reverse tunnel on the victim's machine, allowing attackers to maintain persistent access and exfiltrate data.

IFF Assessment

FOE

This campaign represents a sophisticated attack technique that could lead to significant data breaches and system compromise for defenders.

Defender Context

Defenders should be aware of novel methods for malware delivery and persistence, particularly those that leverage steganography within common file types like PNGs. Monitoring for unusual network connections and reverse tunnel activity on endpoints is crucial for early detection.

Read Full Story →