CYBERSECURITYTRACKER
TRACKING4,485 stories844 vuln stories
Permanent story citation

DOUBLECUP's PNG Payload

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 4898

As cited

Citation snapshot as of .

threat intel

DOUBLECUP's PNG Payload

DOUBLECUP malware appends a PowerShell payload to PNG files, prefixed with carriage-return and newline characters that allow Windows FINDSTR to extract and execute it without custom tools. The technique relies on shell command parsing rather than true steganography or image metadata embedding.

Why it matters: Defenders and endpoint teams should monitor for suspicious PNG files piped to PowerShell and FINDSTR execution chains, as this low-detection-overhead delivery method may enable malware execution on systems with limited logging.

Source published
First seen by Cybersecurity Tracker

Source attribution