PNG Steganography Used by TerminalFix Campaign

TerminalFix threat actors used PNG steganography to evade detection.

Bottom line: TerminalFix threat actors used PNG steganography to evade detection.

What's happening: The TerminalFix campaign, attributed to North Korean hackers, deployed a reverse tunnel through a multistage intrusion. Researchers at Microsoft Security Research published a blog post detailing the campaign. The attackers used a combination of exploits and malware to compromise vulnerable systems. The reverse tunnel allowed the attackers to maintain persistence on compromised systems.

What to do: Security leaders should monitor for PNG files with suspicious activity and consider implementing anti-steganography tools to detect and prevent such attacks. Regularly review system logs to identify potential reverse tunnels and take swift action to contain and remediate affected systems.

Source: SANS Internet Storm Center