Malicious criminals hide malware in imagesin an attempt to evade detection.
See also: AZORult malware spreads via fake Google websites

With cybersecurity software becoming increasingly powerful and detecting more malicious files, attackers are constantly looking for different ways to avoid detection, and among these techniques is the use of malware hidden in images or photos.
It may sound unlikely, but it’s true. Malware embedded in images of various formats is a result of steganography, the technique of hiding data within a file to avoid detection. ESET Research spotted this technique used by the cyberespionage group Worok, which hid malicious code in image files, taking only specific pixel information from them to extract a payload for execution. Keep in mind that this was done on already compromised systems, since as mentioned earlier, embedding malware within images is more about avoiding detection than for initial access.
Typically, malicious images are placed on websites or embedded in documents. Some may remember adware: code hidden in advertisements. On its own, the code in the image cannot be executed or extracted. Another piece of malware that will handle the extraction of the malicious code and its execution. Here the level of user interaction required varies, and how likely someone is to notice malicious activity seems to depend more on the code associated with the extraction than on the image itself.
One of the most malicious ways to embed malware into an image is to replace the least significant bit of each pixel's red-green-blue-alpha (RGBA) value with a small piece of the message. Another technique is to embed the alpha channel of an image (which indicates the transparency of a color), using only a fairly insignificant area. This way, the image looks roughly the same as a normal one, making any difference difficult to detect with the naked eye.
See also: “TicTacToe Droppers” are used to distribute malware

An example of this occurred when legitimate ad networks served ads that potentially led to a malicious banner sent from a compromised server. JavaScript code was extracted from the banner, exploiting the CVE-2016-0162 in some versions of Internet Explorer, to gain more information about the target.
Malware extracted from images can be used for a variety of purposes. In the case of the Explorer vulnerability, the extracted script checks to see if it is running on a monitored computer — such as that of a malware analyst. If not, it is redirected to an exploit page. After exploitation, a final payload is used to deliver malware such as backdoors, trojans, spyware, file stealers, and the like.
As you can see, the difference between a clean and a malicious image is quite small. To a normal person, the malicious image may look a little different, and in this case, the strange appearance could be attributed to poor image quality and resolution, but the reality is that all those dark pixels are an indication of malicious code.
See also: TheMoon malware infected 6,000 ASUS routers
What is the impact of malware on digital security?
Malware is a significant threat to digital security, as it can cause serious damage to a digital system and evade detection, such as by hiding in images. By infiltrating a computer or network, malware can compromise data security, cause information loss or theft, and disrupt system operation. In addition, malware can be used to perform malicious actions, such as espionage, exploiting system resources to launch DDoS , or advertising harassment. These actions can have serious consequences, such as losing customer trust, violating data protection laws, and causing financial loss.
Source: welivesecurity
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
