logo

New FileFix attack uses steganography to drop StealC malware

ID: d11f1520-c112-5184-8736-e9fa2470100d

STIX ID: report--d11f1520-c112-5184-8736-e9fa2470100d

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-09-16

Date Updated: 2026-07-19

Author: Lawrence Abrams

...
...

Acronis uncovered a FileFix campaign that impersonates Meta support to trick victims into pasting a disguised PowerShell command into the File Explorer address bar; the first-stage command downloads a JPG from Bitbucket containing a steganographically embedded second-stage PowerShell script which decrypts and loads the StealC infostealer in memory. StealC harvests browser credentials and cookies, messaging app creds, crypto wallets, cloud credentials, VPN/gaming app data, and can capture screenshots; multiple variants were observed over two weeks, and the campaign leverages detection-evasive techniques (clipboard obfuscation, absence of typical ClickFix markers, and in-memory payload decryption).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.