Bottom line: TerminalFix threat actors used PNG steganography to evade detection.
What's happening: The TerminalFix campaign, attributed to North Korean hackers, deployed a reverse tunnel through a multistage intrusion. Researchers at Microsoft Security Research published a blog post detailing the campaign. The attackers used a combination of exploits and malware to compromise vulnerable systems. The reverse tunnel allowed the attackers to maintain persistence on compromised systems.
What to do: Security leaders should monitor for PNG files with suspicious activity and consider implementing anti-steganography tools to detect and prevent such attacks. Regularly review system logs to identify potential reverse tunnels and take swift action to contain and remediate affected systems.