PNG steganography + reverse tunnel: a new documented variant of stealthy attack

In this saga : Ingénierie sociale via terminal — ClickFix et variantes 2026· Episode 2/3

Cybersecurity Sep 1, 2026Add to bookmarks

PNG steganography + reverse tunnel: a new documented variant of stealthy attack
Illustration : Momiji Shirogane

A campaign conceals malicious code in PNG files via steganography, then deploys a custom reverse tunnel to maintain persistent access. The reverse tunnel technique continues to diversify in its delivery vectors.

What

A new attack campaign documented by The Register combines two techniques to maximize stealth: hiding malware in PNG files via steganography, followed by deployment of a custom reverse tunnel on victim machines. A notable evolution in stealthy delivery techniques that we are tracking in this thread.

Who is impacted

Windows endpoints that may receive PNG files via email, enterprise messaging, or downloads. Environments where outbound traffic is poorly filtered are most exposed.

The attack chain

Step 1 - Malicious PNG Malicious code is encoded in the least significant bits (LSB) of a PNG file’s pixels. The image appears normal. A loader (PowerShell or .NET binary) extracts and executes it.

Step 2 - Discreet execution Steganography bypasses antiviruses that analyze file extensions and known signatures—a PNG is not an executable, so standard detection rules do not apply.

Step 3 - Custom reverse tunnel The malware deploys a homegrown reverse tunnel to its C2 infrastructure. Unlike common tools (ngrok, Frp), this tunnel uses a proprietary protocol that is difficult for application-layer firewalls to block.

What this adds to the picture

In August 2026, we documented TerminalFix: fake Cloudflare CAPTCHA → reverse tunnel backdoor. This new variant uses a radically different delivery vector (PNG image vs. web interface) to achieve the same goal: a persistent reverse tunnel that is hard to detect.

Reverse tunnels as a persistence technique are becoming widespread. Delivery vectors are expanding and diversifying—PNGs, CAPTCHAs, and likely others to come.

What to do now

  • Enable outbound TLS inspection on corporate proxies to detect unusual tunnels
  • Monitor processes initiating unexpected network connections from user endpoints
  • Scan suspicious PNGs received via email with steganography detection tools (zsteg, stegdetect)
  • Apply outbound whitelisting on sensitive endpoints—only allow known destinations
Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

SSHSelf-hostedAI Ops
Get early access
Was this article helpful?

2 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
The saga

Ingénierie sociale via terminal — ClickFix et variantes 2026

  1. 1TerminalFix: fake Cloudflare CAPTCHA, real backdoor in your terminal31/08/2026
  2. 2PNG steganography + reverse tunnel: a new documented variant of stealthy attack01/09/2026
  3. 3Fake software installers: disabling Windows Update and weakening Defender before intrusion03/09/2026
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

Get early access
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information