New FileFix attack uses steganography to drop StealC malware
ID: d11f1520-c112-5184-8736-e9fa2470100d
STIX ID: report--d11f1520-c112-5184-8736-e9fa2470100d
Feed Name: Bleeping Computer
Acronis uncovered a FileFix campaign that impersonates Meta support to trick victims into pasting a disguised PowerShell command into the File Explorer address bar; the first-stage command downloads a JPG from Bitbucket containing a steganographically embedded second-stage PowerShell script which decrypts and loads the StealC infostealer in memory. StealC harvests browser credentials and cookies, messaging app creds, crypto wallets, cloud credentials, VPN/gaming app data, and can capture screenshots; multiple variants were observed over two weeks, and the campaign leverages detection-evasive techniques (clipboard obfuscation, absence of typical ClickFix markers, and in-memory payload decryption).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
