TerminalFix: PNG Steganography, (Mon, Sep 21st)
Microsoft Security Research published an interesting blog post "TerminalFix campaign deploys a reverse tunnel through multistage intrusion" about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganography. I reached out to the researchers and they kindly shared the IOCs for the PNG files with me. The first image is a small PNG file (f5f1eb6d43dd61d5b069c250e5c666384f7417d0c95014773bf9edf8ff13bebe). Analysis with…
Microsoft US