HomeSecurityHackers hide ransomware in JPG images

Hackers hide ransomware in JPG images

A relatively new form of ransomware is becoming increasingly popular, with cybercriminals images JPGto launch attacks that evade traditional security software, according to recent cybersecurity research.

ransomware JPG IMAGES

Hackers inject malicious code into JPG images, bypassing traditional antivirus software. When the user opens the infected image, a hidden loader is activated, triggering a complex three-stage attack :

  1. Stage 1: The image contains a disguised payload that launches a “stager” script.
  2. Stage 2: The stager communicates with a remote server to download the ransomware executable.
  3. Stage 3: The ransomware encrypts the victim's files, demanding payment.

See also: New Mamona ransomware targets Windows systems

Attackers combine the JPG image with another fraudulent document, such as a PDF or Word, which is sent together to increase the likelihood of deceiving the victim. This combination makes it significantly more difficult for security systems to detect.

What makes this attack so dangerous:

  • Zero detection: The attack relies on sophisticated obfuscation and encryption techniques that make it invisible to almost all conventional protection programs.
  • Abuse of trust through Social Engineering: Images and texts are considered "innocent", which makes it easier to deceive victims.
  • Simple processes with high impact: Two files are enough to launch a powerful cyberattack.

See also: Ransomware groups abuse legitimate Kickidler software

One of the experts (Aux Grep) who undertook the technical analysis of this vulnerability described the technique as a "0-day-grade technique with 60% completion", hinting that we may see even more sophisticated and dangerous versions of it in the future.

Cybersecurity companies are already trying to adapt their detection methods to respond to the new threat. Jane Harper , threat analyst at SentinelOne , said: “ This type of attack relies on users’ naive trust in common, everyday files. Organizations need to move to technologies that monitor file behavior, because traditional signature-based antivirus is no longer sufficient .”

At the same time, the FBI issued a warning to businesses, calling on them to:

  • Train staff not to open attachments, even from known senders, if there is suspicion.
  • Integrate security solutions that monitor user interaction with files in real time.
  • Segment corporate networksto limit the spread of ransomware in the event of a breach.

See also: Play ransomware exploits Windows flaw in zero-day attacks

Recommendations for personal protection:

  • Stay up to date on the latest ransomware trends and tactics used by attackers
  • Implement multi-factor authentication (MFA) for all user accounts
  • Enable firewall on all devices connected to your network
  • Keep sensitive data encrypted
  • Update all your devices and systems with the latest security patches
  • Conduct regular security audits and penetration testing
  • Use strong, unique passwords and change them regularly.
  • Limit user access to only necessary systems and information
  • Consider using solutions email security for additional protection against phishing attacks
  • Have a recovery plan to quickly restore systems in the event of an attack
  • Enable the display of file extensions
  • Invest in advanced protection solutions
  • Use sandboxing for email attachments
  • Keep backup copies of your data

Source: gbhackers.com

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS