logo

Pixel perfect Ghostpulse malware loader hides inside PNG image files

ID: a52bc7e6-d535-52ea-b2a3-89c1742b4ac1

STIX ID: report--a52bc7e6-d535-52ea-b2a3-89c1742b4ac1

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-10-22

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Ghostpulse, a loader active since 2023, has been updated to embed and reconstruct its encrypted configuration and payload within PNG image pixels by extracting RGB bytes, validating 16‑byte blocks via CRC32, and XOR‑decrypting the result; this makes detection harder. Operators distribute it using social‑engineering (fake CAPTCHA that copies malicious JavaScript to the clipboard and a PowerShell dropper) to deliver payloads such as the Lumma infostealer, and vendors (Elastic, McAfee) have released or updated detections and YARA rules to counter it.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.