As cited
Citation snapshot as of .
threat intel
DOUBLECUP's PNG Payload
DOUBLECUP malware appends a PowerShell payload to PNG files, prefixed with carriage-return and newline characters that allow Windows FINDSTR to extract and execute it without custom tools. The technique relies on shell command parsing rather than true steganography or image metadata embedding.
Why it matters: Defenders and endpoint teams should monitor for suspicious PNG files piped to PowerShell and FINDSTR execution chains, as this low-detection-overhead delivery method may enable malware execution on systems with limited logging.
- Source published
- First seen by Cybersecurity Tracker