The Register Home Page

back to article Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines

An unknown miscreant is using "TerminalFix" to trick unsuspecting users into running PowerShell commands that infect their computers with a reverse tunnel granting attackers access to their networks. Some of the malware is even hidden inside PNG graphics the PC downloads. TerminalFix is the latest variant of the wildly popular …

  1. Jou (Mxyzptlk) Silver badge

    Aw my gawd...

    I only hope that ONLY private users with their one computer are affected by this. Pleeaase..... I sincerely hope no admin, especially domain admin, fell for this, pleeeeaaaassseee

    @TheReg Jessica Lyons: How many domain admins fell for this?

  2. Evaluator

    What is “powershell” and who is Redmond? Are there better alternatives? Could the vulnerability affect my smartphone? I am very serious about malware. Zero exposure is always my goal.

    1. Anonymous Coward
      Anonymous Coward

      Better find a cave then - others using IT can cause problems too.

      1. Albert Coates Bronze badge

        Whoosh, much?

        1. Anonymous Coward
          Anonymous Coward

          Nah, still too much blood in my caffeine. Now rectified.

          :)

  3. Anon
    Boffin

    "payloads hidden inside PNG images - this is called steganography"

    I was disappointed with the second half of that. Using Piet ( https://dangermouse.net/esoteric/piet.html ) would have shown more enthusiasm and imagination.

  4. This post has been deleted by its author

    1. pc-fluesterer.info

      basically you are right. But you miss the point. Phony overlay happens on a web page, so it's all about he browser.

    2. Jou (Mxyzptlk) Silver badge

      And I thought eNail clients use Black&Decker, Bosch or Makita... (and, if female, add Colsus, Beurer, Grundig...)

    3. doublelayer Silver badge

      Oh this is why? A fake captcha on a website and a PowerShell command has something to do with HTML in email? Well, sounds convincing. I'm always worried when hearing opinions that the people making them either have no clue what they're talking about or haven't bothered to read up on what they're commenting on. Now that we know you wouldn't do either of those things, please go on and tell us what else we need to know.

  5. Anonymous Coward
    Anonymous Coward

    It's 2026

    .. and Microsoft STILL has a problem with images.

    Unbelievable. And yet there are still some who dare call what they throw out every so often "professional".

    1. DJV Silver badge

      Re: Microsoft STILL has a problem with images

      Don't worry, images are not Microslop's ONLY problem area!

    2. Jou (Mxyzptlk) Silver badge

      Re: It's 2026

      .PNG file to transfer data, could have been .jpg etc as well. This is not "Image decoding" issue, the image is simply used to transfer data hidden in it. Whether it is in the compressed extif part, attached binary data at the end or whatever. That is not a Microsoft issue, you can do that nonsense with any OS, it does not even have to decode that actual picture like a web browser you use to check whether it IS a picture (and yes, it is a picture).

      As much as I love bashing MS, especially since Windows 11, the "image" problem here has nothing to do with picture data decoding.

    3. doublelayer Silver badge

      Re: It's 2026

      I see we have eleven people who either didn't read the article or are too stupid to understand what steganography means. You know the bugs that image decoding libraries have had where you can trigger buffer overflows, which incidentally are generally not written by OS people directly? It's not that. Try reading some more.

      1. Jou (Mxyzptlk) Silver badge

        Re: It's 2026

        Yeah man, It's 2026 ! There is a reason why I EXCLUDED stenography and steganography!

  6. pc-fluesterer.info
    Megaphone

    Why did I NEVER see such "phony overlay"?

    Could it be that's because I never surf without the browser add-on NoScript? By default, all JS is blocked. For trusted domains I have to allow it explicitly.

    All of these attacks are based on JS. So if the unknown malicious domain is unable to play the script, no overlay appears or fake BSOD or fake update notice or ... you name it.

    Employ script control!

    1. Anonymous Coward
      Anonymous Coward

      Re: Why did I NEVER see such "phony overlay"?

      because you weren't using a phone?

    2. doublelayer Silver badge

      Re: Why did I NEVER see such "phony overlay"?

      Because you weren't on the site concerned? Blocking JS would remove exactly one part of this, automatically copying the PowerShell script to your clipboard. I don't know whether they did, but it would have been possible and in fact quite easy for them to use HTML alone to have a fake captcha page that displayed the text in a box and had the user copy and paste it. If you were going to tell me that seeing that text would have scared off users, please remember that, even with it copied to the clipboard, they were still instructed to manually launch a PS CLI and paste it in, and if they did it, they would have seen the text before it ran. If you think all the attacks are based on JS, then you are vulnerable from a false sense of security. It would be better to be aware what is possible and therefore on your guard.

      1. pc-fluesterer.info

        Re: Why did I NEVER see such "phony overlay"?

        I am online since > 30 years (in the beginning with Windows even) and I had NEVER a successful attack. Attempts, yes, I saw a lot.

        ALL attempts involving 'clear click' (clickfix) or drive-by downloads rely on JS, at least those I encountered or analyzed just for curiosity.

        Normally the domain bringing malicious JS is != the domain visited.

        1. Anonymous Coward
          Anonymous Coward

          Re: Why did I NEVER see such "phony overlay"?

          I am online since > 30 years (in the beginning with Windows even) and I had NEVER a successful attack

          Somewhere on the Internet: "Challenge accepted.."

  7. Pascal Monett Silver badge
    Windows

    "before the victim pastes it into Windows Terminal or PowerShell"

    And as far as I'm concerned, the attack stops there.

    There is no way I'm going to paste anything anywhere from a CAPTCHA page.

    Not gonna happen.

    That said, I applaud the attacker. Once again, malware writers show a lot more imagination and professionalism that Borkzilla coders.

    How unfortunate that they do not do that kind of work for a legitimate cause.

    1. Jou (Mxyzptlk) Silver badge

      Re: "before the victim pastes it into Windows Terminal or PowerShell"

      Yeah, YOU won't. I won't. The world does :D. Now where is that "the world generates a dumber idiot every time" citation when we need it...

      1. anonymous boring coward Silver badge

        Re: "before the victim pastes it into Windows Terminal or PowerShell"

        It's silly to call normal users "dumb". They just aren't as clued up on things as computer nerds.

        The fault lies entirely with the industry itself. Moronic practices and moronically designed software.

        1. Jou (Mxyzptlk) Silver badge

          Re: "before the victim pastes it into Windows Terminal or PowerShell"

          While this is true, the necessary steps, as written in the article, already require a more advanced user...

          Ask a normal user "open a terminal" oder "open powershell", and then you will see a clueless face (like mine when asking about the history of Belize) 'cause today that is not even remotely expected from a normal user. We are not in the pre Windows 3.1 / MacOS era here, where manuals were still several hundred pages of a book, and were actually written. (MS-DOS 5.0: > 700 pages, for example...)

          1. doublelayer Silver badge

            Re: "before the victim pastes it into Windows Terminal or PowerShell"

            I'm not sure it's that hard to describe to someone how to do it though. The instructions could easily give them the basic steps to open the window and some screenshots, and I think most users would be able to handle that step.

            1. Jou (Mxyzptlk) Silver badge

              Re: "before the victim pastes it into Windows Terminal or PowerShell"

              The'll just say "Hey AI, follow those instructions for me!"

  8. Anonymous Coward
    Anonymous Coward

    Not seen the film, so have no idea what is going on!

  9. Irongut Silver badge

    > train employees on how to look for ClickFix tactics, like fake CAPTCHA verification pages

    That is a moving target as adversaries change their social engineering tactics. Better to train them that if a web page tells them to open the Run dialog or a Terminal window just say "NO".

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon