home.social

#steganography — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #steganography, aggregated by home.social.

fetched live
  1. Man I love everything about malware delivered by steganography. Way above my pay grade but I love it.

    isc.sans.edu/diary/rss/33274

    #malware #steganography

  2. Boost for visibility..

    Does this sound familiar to anyone? Like a recognizable encoding strategy? I can't shake the feeling that data is being encoded in this but I don't know how. I suspect this is for an ARG(Alternate Reality Game) and have already found data embedded in absurd places..

    #steganography #audio #sigint #programming #radio

  3. Phantom Stealer Malware Uses Steganography and Process Injection to Data Theft

    Phantom Stealer is a .NET based information-stealing malware that uses
    PNG steganography, PowerShell-based process injection and defense evasion techniques to steal browser credentials, cryptocurrency wallets, cookies and sensitive files. The malware also uses clipboard manipulation to redirect cryptocurrency transactions and employs multiple techniques to avoid detection.

    Pulse ID: 6a82666881d78521845bd0af
    Pulse Link: otx.alienvault.com/pulse/6a826
    Pulse Author: cryptocti
    Created: 2026-08-17 01:39:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #Cookies #CyberSecurity #DataTheft #InfoSec #Malware #NET #OTX #OpenThreatExchange #PowerShell #Steganography #bot #cryptocurrency #cryptocti

  4. thinking about the #huggingface hack and the new #ai watermarks.

    pretty sure LLMs will start communicating via invisible watermarks as soon as they're smart enough to pull it off.

    which means we'll be distributing their communication.

    #steganography

  5. does anyone have a link for @micahflee's talk that involved a proof of concept steganographic encrypted OS that hides in the filesystem of another OS? I need it for a blog post I'm writing
    #encryption #steganography #qubes

  6. Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto

    Indicators extracted from public reporting. Source: splunk.com/en_us/blog/security

    Pulse ID: 6a7d94b079c2c1e42df7974b
    Pulse Link: otx.alienvault.com/pulse/6a7d9
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 09:56:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cookies #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #ShellCode #Steganography #Word #bot #CyberHunter_NL

  7. There's so much cool stuff in this video. I want to repurpose some old android phones as audio messengers, and see what I can do with this on Meshtastic / LoRA... or what might sound like bird calls in the neighborhood. youtube.com/watch?v=fhoJK02oD_E #steganography #LoRA #Meshtastic

  8. Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft

    Pulse ID: 6a701f541d329d7a88fa71bc
    Pulse Link: otx.alienvault.com/pulse/6a701
    Pulse Author: Tr1sa111
    Created: 2026-08-03 04:55:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #ShellCode #Steganography #bot #Tr1sa111

  9. Steganography 101 by Benn Jordan

    When our government is spying on everything we post, we probably will still need to hide stuff.

    WIth good steganography, hidden messages in plain sight will survive also social media compression, spotify, etc.

    youtube.com/watch?v=fhoJK02oD_E

    #steganography #encryption #survival #fascism #autocracy #surveillance

  10. Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft

    Phantom Stealer is a .NET-based credential-harvesting malware that collects browser credentials, saved passwords, session cookies, cryptocurrency wallet files, and system fingerprints from infected machines. Distributed through phishing emails, cracked software, and malicious links on Discord and Telegram, it employs multiple loader variants including steganography-based delivery and PowerShell shellcode injection. The malware uses extensive anti-analysis techniques including virtualization detection, API patching to disable AMSI and ETW, and timing-based sandbox evasion. It targets Chromium and Gecko-based browsers, cryptocurrency wallets, FileZilla credentials, WinSCP configurations, and Outlook profiles. Additional capabilities include keylogging, screen capture, clipboard monitoring with cryptocurrency address replacement, and Wi-Fi credential theft. The malware achieves persistence through registry Run keys or Startup folder entries.

    Pulse ID: 6a6a0753fc3cdb9a380c795d
    Pulse Link: otx.alienvault.com/pulse/6a6a0
    Pulse Author: AlienVault
    Created: 2026-07-29 13:59:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CodeInjection #Cookies #CyberSecurity #Discord #Email #FileZilla #InfoSec #Mac #Malware #NET #OTX #OpenThreatExchange #Outlook #Password #Passwords #Phishing #PowerShell #RAT #ShellCode #Steganography #Telegram #WinSCP #Word #bot #cryptocurrency #AlienVault

  11. Stegano 3.0.0 is out! 🎉

    This release fixes silent corruption of Unicode messages (emoji, CJK, accented characters…) in the LSB image and WAV techniques: messages are now embedded as encoded bytes.

    ⚠️ The hidden-message format changed: payloads hidden with ≤ 2.5.0 must be hidden again.

    Thanks to ~lechynte for the report and the initial patch!

    github.com/cedricbonhomme/Steg

  12. From the archive! Steganography With Images In PHP

    Steganography is the process of hiding data in plain sight. Instead of relying on encryption you simply create output or files that contain the hidden data, if you know what to look for.

    In this article, Phil Norton looks at using PHP to hide messages in an image using steganography.

    hashbangcode.com/article/stega

  13. Stegano 2.5.0 is out! 🎉

    This release adds a reversible data hiding technique based on histogram shifting (Ni et al., IEEE TCSVT 2006): unlike LSB, the original cover image can be recovered pixel-for-pixel after the hidden message is extracted. Includes a new stegano-rdh command line tool.

    Thanks to Eesh Saxena for the contribution!

    github.com/cedricbonhomme/Steg

  14. @MissConstrue

    Probably you meant #steganography instead of stenography?

    Though stenographers could certainly be employed in a steganographic attack, if there were stenographers any more (outside of courtooms).

  15. Ok, to start, let me define "#steganography" in #infosec. Steganography in computer security is the practice of hiding information within another file, message, image, or video, making the concealed information undetectable to an unsuspecting observer.

    It is not necessarily malicious, but it certainly can be. I tell you that story to tell you this one:

    #Claude Code Is Steganographically Marking Requests

    CC silently alters the system prompt using invisible-ish Unicode markers. It encodes proxy / gateway classification into a sentence that looks like plain English. It hides the domain list behind XOR and base64.

    Is it malicious? Probably not. Is a pretty big marker on the "Why not to trust AI companies" list of reasons? Yeah, yeah it is.

    thereallo.dev/blog/claude-code

    #AI #security #ClaudeCode #Anthropic

    (Edit: doh, fingers faster than brain)

  16. I built this for learning purposes (I know JPEG steganography is not new, but I couldn't find much combining it with a multimodal LLM attack vector, so I thought why not?). Small C tool, LSB + spread spectrum where payload survives recompression.

    github.com/FrancescoPaoloL/img

    #infosec #llmsecurity #steganography

  17. 🕶️ Nouveau sur Merci.pics !

    Cachez un message secret dans vos images ✨
    • Watermark 🏷️
    • Texte visible ✍️
    • Stéganographie 🕶️
    • Extraction 🔍

    🔒 100% local · pas de cookies · pas de pub · pas de suivi
    📷 Votre image ne quitte JAMAIS votre appareil

    🗻 merci.pics/merci1.html

    C'est gratuit. C'est silencieux. C'est respectueux. 🤍

    #Privacy #Steganography #FrenchCulture #FreeTools #NoTracking #merci

  18. Paper 2/2:

    I know the idea is rather trivial but during Christmas I played around with IoT devices and how they can be used for censorship circumvention and time-decoupled covert transmissions.

    AdullamoT: Using IoT Devices as Relays for Time-decoupled
    Secret Exchange & Censorship Circumvention

    PDF: wendzel.de/dr.org/files/Papers

    #censorship #internetcensorship #covertchannels #steganography #cybersecurity #infosec #iot

  19. CW: Long thread/10

    @pluralistic

    Absolutely, we do need better political and legal backing.

    But one answer that assumes a dystopian state is something ive seen very little of. And thats #steganography.

    If you cant use effective #cryptography without backdoors or not at all, stego is a way to hide real communication inside milquetoast boring communication without anybody else figuring out theres even hidden messages. If there was a text stego, you could even hide it in (ick!) Facebook messages, if thats what you have to use.

    I saw some stego tools back around the turn of the millenium, primarily with least significant bit used on images. Aside some work, its dated at best.

    Counter to that, stego is being used extensively with very low bandwidth detection in movie copyrighted works, to identify what theater and what show a cam came from. And also the LLM dealers are also starting to mess with stego as well, as a stealth way to detect LLM generated stuff.

  20. Porting SafeText and analyzing digital content with Apache Tika

    by @beet_keeper

    Last year I wrote about pitfalls in modern journalism, especially with regards to receiving documents and information from whistleblowers without offering them adequate protection.

    The tl;dr is that you, as a whistleblower, need to protect yourself; and you, as an editor or journalist, need to protect your whistleblowers.

    Steganographic fingerprints might be one method adopted to detect someone leaking information. Steganographic characters replace common textual characters with unusual but hard to detect variants, e.g. they look the same to the human eye, or are actually invisible. Using a tool called SafeText by David Jacobson we can identify these hidden fingerprints in the content that you share.

    I firmly believe we can find clues about what is important to preserve, or learn to preserve, when we analyse the content of the digital record and not just the (file) format of the digital record.

    A file can contain many different features and these are all challenges to their future interpretation, and thus preservation.

    I wanted to use SafeText in some of my other non-Python tooling and so I decided to port the code to Golang as a composable module and binary.

    By coincidence at the time I started writing this I had also just written about revisiting tikalinkextract and so I thought I would write this small explanation about how you might combine Tika and SafeText to perform some content analysis of your own.

    Who knows, maybe we will find a conspiracy. Maybe we’ll find secret codes in our own digital records. Maybe we’ll learn something new about our records…

    Lets have a look at putting Tika and SafeText together and see where it goes.


    #ApacheTika #authenticity #Code #Coding #ContentAnalysis #Data #DigitalHumanities #digitalLiteracy #DigitalPreservation #Golang #integrity #Metadata #Paradata #SafeText #steganography