Ghostpulse Virus Lurks in Everyday Photos

Elastic Security Labs Reveals New Methodology for Malicious Data Spread Through PNG Files

Elastic Security Labs a new methodology for the spread of malicious in ghostpulse-downloading data through pngs PNG-File. This approach is named one of the most significant changes in the work of malware since its appearance in 2023.

Previously, Ghostpulse (Hijackloader, Idatloader) was hidden by malicious data in IDAT blocks of PNG files. The new algorithm allows harmful data to be directly introduced into the structure of the image pixels, making detection more challenging.

The new version is already actively used in cyber attacks that employ complex social engineering tactics. For instance, campaigns using Lumma Stealer trick users by presenting them with a problem that is easy for a person to solve but difficult for a computer.

The main concept of the test involves offering users a problem that is simple for a person to solve but exceedingly difficult for a computer. Captcha is a trademark of Carnegie Mellon University, developers of the test.

/Reports, release notes, official announcements.