New PureRAT Campaign Hides PE Payloads in PNG Files and Executes Them Filelessly
ID: 2a09847b-efe2-5fed-97a5-938762a5c9ce
STIX ID: report--2a09847b-efe2-5fed-97a5-938762a5c9ce
Feed Name: cybersecurityNews.com
A sophisticated PureRAT campaign abuses malicious .lnk shortcuts and PowerShell to download PNG images containing Base64-encoded PE payloads hidden via steganography; the payloads are decoded and loaded entirely in memory (fileless execution), use UAC bypass and process hollowing (msbuild.exe) to evade detection, perform host fingerprinting, connect to C2 servers for remote access/keylogging plugins, and maintain persistence via scheduled tasks. The report includes technical details of obfuscation (junk data, .NET Reactor, Triple DES encryption), sandbox-detection checks, and recommended mitigations such as hardening PowerShell policies, restricting abuse of built-in binaries, blocking C2 domains, patching, and user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
