logo

New PureRAT Campaign Uses PNG Files To Conceal Fileless Payloads

ID: b2de90c5-3919-5fc6-b5b4-1985bcfdc2be

STIX ID: report--b2de90c5-3919-5fc6-b5b4-1985bcfdc2be

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-04-21

Date Updated: 2026-04-21

Author: Varshini

...
...

Trellix researchers report a sophisticated PureRAT campaign that begins with a malicious .LNK and VBS loader to download PNG images containing steganographically embedded, obfuscated PE payloads; the attack performs in-memory PowerShell loading (fileless execution), UAC bypass via cmstp.exe, process hollowing, and persistent scheduled tasks, and the report includes SHA256 IOCs and a C2 domain for detection and blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.