#steganography — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #steganography, aggregated by home.social.
-
Stegano 3.0.0 is out! 🎉
This release fixes silent corruption of Unicode messages (emoji, CJK, accented characters…) in the LSB image and WAV techniques: messages are now embedded as encoded bytes.
⚠️ The hidden-message format changed: payloads hidden with ≤ 2.5.0 must be hidden again.
Thanks to ~lechynte for the report and the initial patch!
https://github.com/cedricbonhomme/Stegano/releases/tag/v3.0.0
-
Stegano 3.0.0 is out! 🎉
This release fixes silent corruption of Unicode messages (emoji, CJK, accented characters…) in the LSB image and WAV techniques: messages are now embedded as encoded bytes.
⚠️ The hidden-message format changed: payloads hidden with ≤ 2.5.0 must be hidden again.
Thanks to ~lechynte for the report and the initial patch!
https://github.com/cedricbonhomme/Stegano/releases/tag/v3.0.0
-
Stegano 3.0.0 is out! 🎉
This release fixes silent corruption of Unicode messages (emoji, CJK, accented characters…) in the LSB image and WAV techniques: messages are now embedded as encoded bytes.
⚠️ The hidden-message format changed: payloads hidden with ≤ 2.5.0 must be hidden again.
Thanks to ~lechynte for the report and the initial patch!
https://github.com/cedricbonhomme/Stegano/releases/tag/v3.0.0
-
Stegano 3.0.0 is out! 🎉
This release fixes silent corruption of Unicode messages (emoji, CJK, accented characters…) in the LSB image and WAV techniques: messages are now embedded as encoded bytes.
⚠️ The hidden-message format changed: payloads hidden with ≤ 2.5.0 must be hidden again.
Thanks to ~lechynte for the report and the initial patch!
https://github.com/cedricbonhomme/Stegano/releases/tag/v3.0.0
-
Stegano 3.0.0 is out! 🎉
This release fixes silent corruption of Unicode messages (emoji, CJK, accented characters…) in the LSB image and WAV techniques: messages are now embedded as encoded bytes.
⚠️ The hidden-message format changed: payloads hidden with ≤ 2.5.0 must be hidden again.
Thanks to ~lechynte for the report and the initial patch!
https://github.com/cedricbonhomme/Stegano/releases/tag/v3.0.0
-
Contagious Interview malware in SVG images: DPRK campaign
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.
Pulse ID: 6a5a8ba0229db5a5b2686baa
Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa
Pulse Author: AlienVault
Created: 2026-07-17 20:08:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
-
Contagious Interview malware in SVG images: DPRK campaign
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.
Pulse ID: 6a5a8ba0229db5a5b2686baa
Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa
Pulse Author: AlienVault
Created: 2026-07-17 20:08:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
-
Contagious Interview malware in SVG images: DPRK campaign
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.
Pulse ID: 6a5a8ba0229db5a5b2686baa
Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa
Pulse Author: AlienVault
Created: 2026-07-17 20:08:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
-
Contagious Interview malware in SVG images: DPRK campaign
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.
Pulse ID: 6a5a8ba0229db5a5b2686baa
Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa
Pulse Author: AlienVault
Created: 2026-07-17 20:08:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
-
Contagious Interview malware in SVG images: DPRK campaign
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.
Pulse ID: 6a5a8ba0229db5a5b2686baa
Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa
Pulse Author: AlienVault
Created: 2026-07-17 20:08:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
-
ACR Stealer: Two observed intrusion chains amid increased threat activity
Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop technique enabled dynamic i...
Pulse ID: 6a59832ac2ebd9e525a462b9
Pulse Link: https://otx.alienvault.com/pulse/6a59832ac2ebd9e525a462b9
Pulse Author: AlienVault
Created: 2026-07-17 01:19:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #CyberSecurity #ICS #InfoSec #Malware #MalwareAsAService #Microsoft #OTX #OpenThreatExchange #PDF #PowerShell #Python #SocialEngineering #Steganography #Windows #bot #AlienVault
-
ACR Stealer: Two observed intrusion chains amid increased threat activity
Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop technique enabled dynamic i...
Pulse ID: 6a59832ac2ebd9e525a462b9
Pulse Link: https://otx.alienvault.com/pulse/6a59832ac2ebd9e525a462b9
Pulse Author: AlienVault
Created: 2026-07-17 01:19:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #CyberSecurity #ICS #InfoSec #Malware #MalwareAsAService #Microsoft #OTX #OpenThreatExchange #PDF #PowerShell #Python #SocialEngineering #Steganography #Windows #bot #AlienVault
-
ACR Stealer: Two observed intrusion chains amid increased threat activity
Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop technique enabled dynamic i...
Pulse ID: 6a59832ac2ebd9e525a462b9
Pulse Link: https://otx.alienvault.com/pulse/6a59832ac2ebd9e525a462b9
Pulse Author: AlienVault
Created: 2026-07-17 01:19:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #CyberSecurity #ICS #InfoSec #Malware #MalwareAsAService #Microsoft #OTX #OpenThreatExchange #PDF #PowerShell #Python #SocialEngineering #Steganography #Windows #bot #AlienVault
-
ACR Stealer: Two observed intrusion chains amid increased threat activity
Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop technique enabled dynamic i...
Pulse ID: 6a59832ac2ebd9e525a462b9
Pulse Link: https://otx.alienvault.com/pulse/6a59832ac2ebd9e525a462b9
Pulse Author: AlienVault
Created: 2026-07-17 01:19:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #CyberSecurity #ICS #InfoSec #Malware #MalwareAsAService #Microsoft #OTX #OpenThreatExchange #PDF #PowerShell #Python #SocialEngineering #Steganography #Windows #bot #AlienVault
-
ACR Stealer: Two observed intrusion chains amid increased threat activity
Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop technique enabled dynamic i...
Pulse ID: 6a59832ac2ebd9e525a462b9
Pulse Link: https://otx.alienvault.com/pulse/6a59832ac2ebd9e525a462b9
Pulse Author: AlienVault
Created: 2026-07-17 01:19:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #CyberSecurity #ICS #InfoSec #Malware #MalwareAsAService #Microsoft #OTX #OpenThreatExchange #PDF #PowerShell #Python #SocialEngineering #Steganography #Windows #bot #AlienVault
-
Need to hide a message in plain sight? Steganography lets you embed secret data inside images, audio, or text without drawing attention
Here are some free steganography tools to check out 😎👇
Find a high-res pdf ebook with all my cybersecurity related infographics from https://study-notes.org/
#cybersecurity #infosec #informationsecurity #datasecurity #steganography
-
Need to hide a message in plain sight? Steganography lets you embed secret data inside images, audio, or text without drawing attention
Here are some free steganography tools to check out 😎👇
Find a high-res pdf ebook with all my cybersecurity related infographics from https://study-notes.org/
#cybersecurity #infosec #informationsecurity #datasecurity #steganography
-
Need to hide a message in plain sight? Steganography lets you embed secret data inside images, audio, or text without drawing attention
Here are some free steganography tools to check out 😎👇
Find a high-res pdf ebook with all my cybersecurity related infographics from https://study-notes.org/
#cybersecurity #infosec #informationsecurity #datasecurity #steganography
-
Need to hide a message in plain sight? Steganography lets you embed secret data inside images, audio, or text without drawing attention
Here are some free steganography tools to check out 😎👇
Find a high-res pdf ebook with all my cybersecurity related infographics from https://study-notes.org/
#cybersecurity #infosec #informationsecurity #datasecurity #steganography
-
From the archive! Steganography With Images In PHP
Steganography is the process of hiding data in plain sight. Instead of relying on encryption you simply create output or files that contain the hidden data, if you know what to look for.
In this article, Phil Norton looks at using PHP to hide messages in an image using steganography.
https://www.hashbangcode.com/article/steganography-images-php
#php #steganography #hashbangcode -
From the archive! Steganography With Images In PHP
Steganography is the process of hiding data in plain sight. Instead of relying on encryption you simply create output or files that contain the hidden data, if you know what to look for.
In this article, Phil Norton looks at using PHP to hide messages in an image using steganography.
https://www.hashbangcode.com/article/steganography-images-php
#php #steganography #hashbangcode -
From the archive! Steganography With Images In PHP
Steganography is the process of hiding data in plain sight. Instead of relying on encryption you simply create output or files that contain the hidden data, if you know what to look for.
In this article, Phil Norton looks at using PHP to hide messages in an image using steganography.
https://www.hashbangcode.com/article/steganography-images-php
#php #steganography #hashbangcode -
From the archive! Steganography With Images In PHP
Steganography is the process of hiding data in plain sight. Instead of relying on encryption you simply create output or files that contain the hidden data, if you know what to look for.
In this article, Phil Norton looks at using PHP to hide messages in an image using steganography.
https://www.hashbangcode.com/article/steganography-images-php
#php #steganography #hashbangcode -
Stegano 2.5.0 is out! 🎉
This release adds a reversible data hiding technique based on histogram shifting (Ni et al., IEEE TCSVT 2006): unlike LSB, the original cover image can be recovered pixel-for-pixel after the hidden message is extracted. Includes a new stegano-rdh command line tool.
Thanks to Eesh Saxena for the contribution!
https://github.com/cedricbonhomme/Stegano/releases/tag/v2.5.0
-
Stegano 2.5.0 is out! 🎉
This release adds a reversible data hiding technique based on histogram shifting (Ni et al., IEEE TCSVT 2006): unlike LSB, the original cover image can be recovered pixel-for-pixel after the hidden message is extracted. Includes a new stegano-rdh command line tool.
Thanks to Eesh Saxena for the contribution!
https://github.com/cedricbonhomme/Stegano/releases/tag/v2.5.0
-
Stegano 2.5.0 is out! 🎉
This release adds a reversible data hiding technique based on histogram shifting (Ni et al., IEEE TCSVT 2006): unlike LSB, the original cover image can be recovered pixel-for-pixel after the hidden message is extracted. Includes a new stegano-rdh command line tool.
Thanks to Eesh Saxena for the contribution!
https://github.com/cedricbonhomme/Stegano/releases/tag/v2.5.0
-
Stegano 2.5.0 is out! 🎉
This release adds a reversible data hiding technique based on histogram shifting (Ni et al., IEEE TCSVT 2006): unlike LSB, the original cover image can be recovered pixel-for-pixel after the hidden message is extracted. Includes a new stegano-rdh command line tool.
Thanks to Eesh Saxena for the contribution!
https://github.com/cedricbonhomme/Stegano/releases/tag/v2.5.0
-
Stegano 2.5.0 is out! 🎉
This release adds a reversible data hiding technique based on histogram shifting (Ni et al., IEEE TCSVT 2006): unlike LSB, the original cover image can be recovered pixel-for-pixel after the hidden message is extracted. Includes a new stegano-rdh command line tool.
Thanks to Eesh Saxena for the contribution!
https://github.com/cedricbonhomme/Stegano/releases/tag/v2.5.0
-
In which #Anthropic tries to thwart Chinese LLM makers using sloppy #steganography in #ClaudeCode 🤦🏽♂️:
“Claude Code Is Steganographically Marking Requests”, ‘Thereallo’ (https://thereallo.dev/blog/claude-code-prompt-steganography).
-
In which #Anthropic tries to thwart Chinese LLM makers using sloppy #steganography in #ClaudeCode 🤦🏽♂️:
“Claude Code Is Steganographically Marking Requests”, ‘Thereallo’ (https://thereallo.dev/blog/claude-code-prompt-steganography).
-
In which #Anthropic tries to thwart Chinese LLM makers using sloppy #steganography in #ClaudeCode 🤦🏽♂️:
“Claude Code Is Steganographically Marking Requests”, ‘Thereallo’ (https://thereallo.dev/blog/claude-code-prompt-steganography).
-
In which #Anthropic tries to thwart Chinese LLM makers using sloppy #steganography in #ClaudeCode 🤦🏽♂️:
“Claude Code Is Steganographically Marking Requests”, ‘Thereallo’ (https://thereallo.dev/blog/claude-code-prompt-steganography).
-
AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign
A widespread phishing campaign distributing AsyncRAT and Remcos RATs has been observed targeting organizations across manufacturing, media, professional services, agriculture, and chemical industries globally. The attack leverages malicious Excel spreadsheets sent via emails impersonating business communications like purchase orders and payment advice. When macros are enabled, VBA code retrieves HTA payloads through URL shorteners and Cloudflare Workers infrastructure. The multi-stage infection chain employs heavy obfuscation including Base64 encoding, steganography in PNG files, and character substitution. The campaign intensified during June 2026, affecting organizations across Europe, Asia-Pacific, and the Americas. Infrastructure includes distinctive HTA naming conventions using concatenated positive English words. The operation likely uses automation for payload generation and may leverage LLMs for development efficiency.
Pulse ID: 6a471de4dcdacfc396979ab8
Pulse Link: https://otx.alienvault.com/pulse/6a471de4dcdacfc396979ab8
Pulse Author: AlienVault
Created: 2026-07-03 02:26:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Americas #Asia #AsyncRAT #Cloud #CyberSecurity #Email #Europe #Excel #InfoSec #Mac #Manufacturing #OTX #OpenThreatExchange #Phishing #RAT #Remcos #RemcosRAT #Steganography #Word #bot #AlienVault
-
AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign
A widespread phishing campaign distributing AsyncRAT and Remcos RATs has been observed targeting organizations across manufacturing, media, professional services, agriculture, and chemical industries globally. The attack leverages malicious Excel spreadsheets sent via emails impersonating business communications like purchase orders and payment advice. When macros are enabled, VBA code retrieves HTA payloads through URL shorteners and Cloudflare Workers infrastructure. The multi-stage infection chain employs heavy obfuscation including Base64 encoding, steganography in PNG files, and character substitution. The campaign intensified during June 2026, affecting organizations across Europe, Asia-Pacific, and the Americas. Infrastructure includes distinctive HTA naming conventions using concatenated positive English words. The operation likely uses automation for payload generation and may leverage LLMs for development efficiency.
Pulse ID: 6a471de4dcdacfc396979ab8
Pulse Link: https://otx.alienvault.com/pulse/6a471de4dcdacfc396979ab8
Pulse Author: AlienVault
Created: 2026-07-03 02:26:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Americas #Asia #AsyncRAT #Cloud #CyberSecurity #Email #Europe #Excel #InfoSec #Mac #Manufacturing #OTX #OpenThreatExchange #Phishing #RAT #Remcos #RemcosRAT #Steganography #Word #bot #AlienVault
-
AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign
A widespread phishing campaign distributing AsyncRAT and Remcos RATs has been observed targeting organizations across manufacturing, media, professional services, agriculture, and chemical industries globally. The attack leverages malicious Excel spreadsheets sent via emails impersonating business communications like purchase orders and payment advice. When macros are enabled, VBA code retrieves HTA payloads through URL shorteners and Cloudflare Workers infrastructure. The multi-stage infection chain employs heavy obfuscation including Base64 encoding, steganography in PNG files, and character substitution. The campaign intensified during June 2026, affecting organizations across Europe, Asia-Pacific, and the Americas. Infrastructure includes distinctive HTA naming conventions using concatenated positive English words. The operation likely uses automation for payload generation and may leverage LLMs for development efficiency.
Pulse ID: 6a471de4dcdacfc396979ab8
Pulse Link: https://otx.alienvault.com/pulse/6a471de4dcdacfc396979ab8
Pulse Author: AlienVault
Created: 2026-07-03 02:26:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Americas #Asia #AsyncRAT #Cloud #CyberSecurity #Email #Europe #Excel #InfoSec #Mac #Manufacturing #OTX #OpenThreatExchange #Phishing #RAT #Remcos #RemcosRAT #Steganography #Word #bot #AlienVault
-
AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign
A widespread phishing campaign distributing AsyncRAT and Remcos RATs has been observed targeting organizations across manufacturing, media, professional services, agriculture, and chemical industries globally. The attack leverages malicious Excel spreadsheets sent via emails impersonating business communications like purchase orders and payment advice. When macros are enabled, VBA code retrieves HTA payloads through URL shorteners and Cloudflare Workers infrastructure. The multi-stage infection chain employs heavy obfuscation including Base64 encoding, steganography in PNG files, and character substitution. The campaign intensified during June 2026, affecting organizations across Europe, Asia-Pacific, and the Americas. Infrastructure includes distinctive HTA naming conventions using concatenated positive English words. The operation likely uses automation for payload generation and may leverage LLMs for development efficiency.
Pulse ID: 6a471de4dcdacfc396979ab8
Pulse Link: https://otx.alienvault.com/pulse/6a471de4dcdacfc396979ab8
Pulse Author: AlienVault
Created: 2026-07-03 02:26:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Americas #Asia #AsyncRAT #Cloud #CyberSecurity #Email #Europe #Excel #InfoSec #Mac #Manufacturing #OTX #OpenThreatExchange #Phishing #RAT #Remcos #RemcosRAT #Steganography #Word #bot #AlienVault
-
AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign
A widespread phishing campaign distributing AsyncRAT and Remcos RATs has been observed targeting organizations across manufacturing, media, professional services, agriculture, and chemical industries globally. The attack leverages malicious Excel spreadsheets sent via emails impersonating business communications like purchase orders and payment advice. When macros are enabled, VBA code retrieves HTA payloads through URL shorteners and Cloudflare Workers infrastructure. The multi-stage infection chain employs heavy obfuscation including Base64 encoding, steganography in PNG files, and character substitution. The campaign intensified during June 2026, affecting organizations across Europe, Asia-Pacific, and the Americas. Infrastructure includes distinctive HTA naming conventions using concatenated positive English words. The operation likely uses automation for payload generation and may leverage LLMs for development efficiency.
Pulse ID: 6a471de4dcdacfc396979ab8
Pulse Link: https://otx.alienvault.com/pulse/6a471de4dcdacfc396979ab8
Pulse Author: AlienVault
Created: 2026-07-03 02:26:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Americas #Asia #AsyncRAT #Cloud #CyberSecurity #Email #Europe #Excel #InfoSec #Mac #Manufacturing #OTX #OpenThreatExchange #Phishing #RAT #Remcos #RemcosRAT #Steganography #Word #bot #AlienVault
-
Probably you meant #steganography instead of stenography?
Though stenographers could certainly be employed in a steganographic attack, if there were stenographers any more (outside of courtooms).
-
Probably you meant #steganography instead of stenography?
Though stenographers could certainly be employed in a steganographic attack, if there were stenographers any more (outside of courtooms).
-
Probably you meant #steganography instead of stenography?
Though stenographers could certainly be employed in a steganographic attack, if there were stenographers any more (outside of courtooms).
-
Probably you meant #steganography instead of stenography?
Though stenographers could certainly be employed in a steganographic attack, if there were stenographers any more (outside of courtooms).
-
Probably you meant #steganography instead of stenography?
Though stenographers could certainly be employed in a steganographic attack, if there were stenographers any more (outside of courtooms).
-
Ok, to start, let me define "#steganography" in #infosec. Steganography in computer security is the practice of hiding information within another file, message, image, or video, making the concealed information undetectable to an unsuspecting observer.
It is not necessarily malicious, but it certainly can be. I tell you that story to tell you this one:
#Claude Code Is Steganographically Marking Requests
CC silently alters the system prompt using invisible-ish Unicode markers. It encodes proxy / gateway classification into a sentence that looks like plain English. It hides the domain list behind XOR and base64.
Is it malicious? Probably not. Is a pretty big marker on the "Why not to trust AI companies" list of reasons? Yeah, yeah it is.
https://thereallo.dev/blog/claude-code-prompt-steganography
#AI #security #ClaudeCode #Anthropic
(Edit: doh, fingers faster than brain)
-
Ok, to start, let me define "#steganography" in #infosec. Steganography in computer security is the practice of hiding information within another file, message, image, or video, making the concealed information undetectable to an unsuspecting observer.
It is not necessarily malicious, but it certainly can be. I tell you that story to tell you this one:
#Claude Code Is Steganographically Marking Requests
CC silently alters the system prompt using invisible-ish Unicode markers. It encodes proxy / gateway classification into a sentence that looks like plain English. It hides the domain list behind XOR and base64.
Is it malicious? Probably not. Is a pretty big marker on the "Why not to trust AI companies" list of reasons? Yeah, yeah it is.
https://thereallo.dev/blog/claude-code-prompt-steganography
#AI #security #ClaudeCode #Anthropic
(Edit: doh, fingers faster than brain)
-
Ok, to start, let me define "#steganography" in #infosec. Steganography in computer security is the practice of hiding information within another file, message, image, or video, making the concealed information undetectable to an unsuspecting observer.
It is not necessarily malicious, but it certainly can be. I tell you that story to tell you this one:
#Claude Code Is Steganographically Marking Requests
CC silently alters the system prompt using invisible-ish Unicode markers. It encodes proxy / gateway classification into a sentence that looks like plain English. It hides the domain list behind XOR and base64.
Is it malicious? Probably not. Is a pretty big marker on the "Why not to trust AI companies" list of reasons? Yeah, yeah it is.
https://thereallo.dev/blog/claude-code-prompt-steganography
#AI #security #ClaudeCode #Anthropic
(Edit: doh, fingers faster than brain)
-
Ok, to start, let me define "#steganography" in #infosec. Steganography in computer security is the practice of hiding information within another file, message, image, or video, making the concealed information undetectable to an unsuspecting observer.
It is not necessarily malicious, but it certainly can be. I tell you that story to tell you this one:
#Claude Code Is Steganographically Marking Requests
CC silently alters the system prompt using invisible-ish Unicode markers. It encodes proxy / gateway classification into a sentence that looks like plain English. It hides the domain list behind XOR and base64.
Is it malicious? Probably not. Is a pretty big marker on the "Why not to trust AI companies" list of reasons? Yeah, yeah it is.
https://thereallo.dev/blog/claude-code-prompt-steganography
#AI #security #ClaudeCode #Anthropic
(Edit: doh, fingers faster than brain)
-
Ok, to start, let me define "#steganography" in #infosec. Steganography in computer security is the practice of hiding information within another file, message, image, or video, making the concealed information undetectable to an unsuspecting observer.
It is not necessarily malicious, but it certainly can be. I tell you that story to tell you this one:
#Claude Code Is Steganographically Marking Requests
CC silently alters the system prompt using invisible-ish Unicode markers. It encodes proxy / gateway classification into a sentence that looks like plain English. It hides the domain list behind XOR and base64.
Is it malicious? Probably not. Is a pretty big marker on the "Why not to trust AI companies" list of reasons? Yeah, yeah it is.
https://thereallo.dev/blog/claude-code-prompt-steganography
#AI #security #ClaudeCode #Anthropic
(Edit: doh, fingers faster than brain)
-
Claude Code Is Steganographically Marking Requests
https://thereallo.dev/blog/claude-code-prompt-steganography
#HackerNews #ClaudeCode #Steganography #Requests #TechNews #AIResearch
-
Claude Code Is Steganographically Marking Requests
https://thereallo.dev/blog/claude-code-prompt-steganography
#HackerNews #ClaudeCode #Steganography #Requests #TechNews #AIResearch
-
Claude Code Is Steganographically Marking Requests
https://thereallo.dev/blog/claude-code-prompt-steganography
#HackerNews #ClaudeCode #Steganography #Requests #TechNews #AIResearch