Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines
ID: ea826969-ac58-5648-a6c9-1cc93d708075
STIX ID: report--ea826969-ac58-5648-a6c9-1cc93d708075
Feed Name: The Register (Security)
Microsoft researchers observed a TerminalFix campaign that lures users into pasting a fake Cloudflare verification command into Windows Terminal/PowerShell; the command runs a hidden PowerShell script that extracts a ZIP, uses a signed executable (LockScreenContentServer.exe) for DLL sideloading of a malicious dui70.dll, and then downloads split payloads hidden inside PNGs. The malware establishes persistence via Run keys and scheduled tasks, performs Active Directory and infrastructure reconnaissance, installs a file-watch backdoor for remote PowerShell execution, and deploys a Python-based reverse WebSocket tunnel (pythonw.exe to gitnow.dev:443) to provide attackers persistent SOCKS-style network access through compromised hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
