Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

TerminalFix Malware Campaign Uses PNG Steganography to Hide Reverse‑Tunnel Payloads

Microsoft Security Research identified a campaign that hides malicious code inside PNG images using steganography, then opens a reverse tunnel for persistence. The technique highlights gaps in file‑type controls and underscores the need for continuous monitoring and auditable evidence of detection.

LiveThreat™ Intelligence · 📅 September 21, 2026· 📰 isc.sans.edu
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
isc.sans.edu

TerminalFix Malware Campaign Uses PNG Steganography to Hide Reverse‑Tunnel Payloads

What Happened — Microsoft Security Research disclosed a multi‑stage intrusion campaign dubbed TerminalFix. The actors embed malicious code inside seemingly benign PNG images using steganography, then launch a reverse tunnel to maintain persistence and exfiltrate data. Researchers published indicators of compromise (IOCs) for the compromised PNG files.

Why It Matters for Trust & Control Assurance

  • Attackers can evade file‑type filters by hiding payloads in legitimate image formats, exposing gaps in detection and logging controls.
  • Continuous monitoring of file integrity and outbound network connections is a core control objective that a robust control‑assurance program must evidence.
  • Verisq’s Control Mapping capability helps map these detection gaps to multiple frameworks and provides auditable evidence of remediation.

Who Is Affected – Any organization that accepts PNG uploads (web portals, email gateways, CMS platforms, SaaS applications) across all industry sectors.

Recommended Actions

  • Augment file‑inspection pipelines with steganography detection or hash‑based whitelisting.
  • Enforce outbound network traffic monitoring to flag unexpected reverse‑tunnel connections.
  • Integrate the published IOCs into SIEM/EDR rule sets and retain evidence for audit readiness.

Source: Microsoft Security Research blog

Technical Notes – The campaign leverages PNG steganography to conceal a reverse‑tunnel payload, bypassing conventional file‑type filters. The tunnel is established over common ports (e.g., 443) to blend with legitimate traffic. No specific CVE is involved; the technique is a delivery‑method abuse. Source: same as above

📰 Original Source
https://isc.sans.edu/diary/rss/33318 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →