logo

Tricks and Treats: GHOSTPULSE’s new pixel-level deception

ID: d3ec5ece-54f7-5285-8c51-68fe330d526f

STIX ID: report--d3ec5ece-54f7-5285-8c51-68fe330d526f

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2024-10-19

Date Updated: 2026-04-27

...
...

This Elastic Security Labs update documents a significant change to the GHOSTPULSE loader: instead of hiding encrypted payloads in PNG IDAT chunks, the malware now encodes configuration and payload data within image pixel RGB values and extracts it via GDI+ APIs. The report describes active campaigns delivering LUMMA STEALER through malicious social engineering (CAPTCHA-like prompts that execute PowerShell via clipboard/keyboard shortcuts), provides IOCs (SHA-256 hashes and domains), and supplies updated detection resources including YARA rules and a configuration extractor tool.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.