The popularity of PNG files and their widespread use on the internet make them attractive targets for malicious actors.

Steganography allows malicious code to be hidden within these files. Recently, researchers from Elastic Security discovered that the GHOSTPULSE malware hides in the pixel structure of PNG files to avoid detection.
See also: Latrodectus malware is back – New phishing attacks
The GHOSTPULSE, also known as HIJACKLOADER or IDATLOADER, has evolved since its initial appearance in 2023, when it used IDAT sections of PNGs to hide malicious payloads. The latest version exploits advanced techniques, such as embedding the “payload” directly into image pixels, parsing the RGB values and creating a byte array.
This new method enhances GHOSTPULSE's ability to evade detection, with recent gangs presenting it as a single executable file. Elastic researchers are addressing this challenge by improving the configuration extraction tool, which analyzes PNGs to identify and extract the malicious payload.
The original YARA rule remains effective in detecting the first form of infection, while new YARA rules have been developed to identify updated variants of GHOSTPULSE.
Read more: WordPress sites hacked: Fake plugins promote info-stealer malware

This advanced configuration extractor empowers researchers to better understand and combat the ever-changing tactics of malware, highlighting the importance of adapting to cybersecurity.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
