logo

Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines

ID: ea826969-ac58-5648-a6c9-1cc93d708075

STIX ID: report--ea826969-ac58-5648-a6c9-1cc93d708075

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-08-31

Date Updated: 2026-09-01

...
...

Microsoft researchers observed a TerminalFix campaign that lures users into pasting a fake Cloudflare verification command into Windows Terminal/PowerShell; the command runs a hidden PowerShell script that extracts a ZIP, uses a signed executable (LockScreenContentServer.exe) for DLL sideloading of a malicious dui70.dll, and then downloads split payloads hidden inside PNGs. The malware establishes persistence via Run keys and scheduled tasks, performs Active Directory and infrastructure reconnaissance, installs a file-watch backdoor for remote PowerShell execution, and deploys a Python-based reverse WebSocket tunnel (pythonw.exe to gitnow.dev:443) to provide attackers persistent SOCKS-style network access through compromised hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.