In the past, security researchers have encountered cases where notorious hackers were able to use EXIF data of images to hide malicious code. This technique is still widely used to infect web users with malware.
Taking it a step further, it was found that hackers have found a way to distribute malware via trusted Google, such as those at googleusercontent. Unlike malware stored in text files, malicious payloads in images are much harder to detect. Furthermore, it is even more difficult to report malware located on googleusercontent.com to Google.
For those who don't know, googleusercontent is Google's domain for displaying user-provided content, without affecting the security of Google pages.
According to a report by Sucuri, the following code was found in a script that extracts the PayPal security code:

The script reads EXIF data from an image on googleusercontent, which was likely uploaded by someone on a Google+ or Blogger account. When the UserComment section of the EXIF data was decoded, it turned out to be a script that has the ability to upload web shells and arbitrary files.
This indicates a larger threat, as there is no way to detect the malware until the image metadata is checked and decoded. Even after the malware is identified, no one can know the true source of the image.
