malware DOUBLECUP's PNG Payload, (Mon, Aug 24th) A new DOUBLECUP malware campaign utilizes a clever technique to bypass traditional steganography detection. The malware, delivered via PNG images, uses a simple PowerShell script appended to the file, easily extracted using the Windows `FINDSTR` command, avoiding the need for specialized extraction tools. SANS Internet Storm Center · 6d ago Medium powershellsteganographywindows
threat-intel DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT DOUBLECUP, a new Russian LaaS service, is using ClickFix lures to deliver malware, specifically CountLoader (Windows and macOS) and DeviceManager (Windows and macOS). DeviceManager utilizes blockchain-based C2 resolution… The Hacker News · Aug 4, 2026 High RUsteganographyclickfixransomware
threat-intel Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images North Korean threat actors, linked to the Contagious Interview campaign (REF9403), are using fake coding tests and SVG images containing steganography to deliver a multi-stage malware payload – OtterCookie – to software… The Hacker News · Jul 17, 2026 High KPsteganographysupply chaindeveloper
malware Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures The Ousaban banking trojan, originating in Brazil and previously tracked as Javali, is targeting Windows users in Spain and Portugal with a phishing campaign utilizing fake PDF lures. The trojan, which has evolved over t… The Hacker News · Jul 1, 2026 High PTESbanking trojanphishinggeofencing
malware Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts Microsoft removed 119 malicious Edge extensions from its add-on store that employed steganography to hide malware, including credential theft and ad fraud capabilities. The operation, dubbed StegoAd, had been active sinc… The Hacker News · Jun 29, 2026 High CHsteganographycredential theftad fraud
threat-intel LLMs and Text-in-Text Steganography This article discusses attempts to hide text within LLMs using techniques like phonological changes and unconventional formatting (e.g., white text on white backgrounds). The author explores the limitations of these meth… Schneier on Security · May 11, 2026 Low UKsteganographyllmstempeset