← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 21, 2026 · 10:33via SANS Internet Storm Center

TerminalFix: PNG Steganography, (Mon, Sep 21st)

Brief

Microsoft Security Research published an interesting blog post "TerminalFix campaign deploys a reverse tunnel through multistage intrusion" about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganography. I reached out to the researchers and they kindly shared the IOCs for the PNG files with me.

Read more on SANS Internet Storm Center→