Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines
Summary
A new malware campaign, dubbed "ClickFix," employs a multi-stage attack chain that conceals malicious code within PNG image files. Once executed, the malware establishes a custom reverse tunnel on the victim's machine, allowing attackers to maintain persistent access and exfiltrate data.
IFF Assessment
FOE
This campaign represents a sophisticated attack technique that could lead to significant data breaches and system compromise for defenders.
Defender Context
Defenders should be aware of novel methods for malware delivery and persistence, particularly those that leverage steganography within common file types like PNGs. Monitoring for unusual network connections and reverse tunnel activity on endpoints is crucial for early detection.