Monday, June 16, 2025
Homecyber securityGHOSTPULSE Hides Within PNG File Pixel Structure To Evade Detections

GHOSTPULSE Hides Within PNG File Pixel Structure To Evade Detections

Published on

SIEM as a Service

Follow Us on Google News

Recent campaigns targeting victims through social engineering tactics utilize LUMMA STEALER with GHOSTPULSE as its loader.

By tricking victims into executing a series of Windows keyboard shortcuts, malicious JavaScript is executed, leading to the execution of a PowerShell script. 

The script downloads and executes a GHOSTPULSE payload, which is now a single executable file containing the encrypted configuration within its resources section. This simplifies the malware’s deployment process.

- Advertisement - Google News
Large embedded PNG file in the resources section
Large embedded PNG file in the resources section

It has undergone a significant update, primarily affecting its configuration retrieval method, where previously, it would extract encrypted data from a PNG file by searching for specific markers and tags, which involved sequentially parsing the file and extracting chunks based on matching identifiers. 

Join ANY.RUN's FREE webinar on How to Improve Threat Investigations on Oct 23 - Register Here 

The new version implements a more complex approach, likely involving different hashing algorithms and data structures to locate and retrieve the configuration.

This approach aims to enhance the malware’s resilience against detection and analysis, making it more difficult to track and mitigate its impact.

Pseudocode code comparison between old and new algorithm
Pseudocode code comparison between old and new algorithm

The malware encrypts its configuration within the pixels of an image, which extracts the RGB values from each pixel to construct a byte array.

By iterating through the byte array in 16-byte blocks and comparing CRC32 hashes, the malware locates the encrypted GHOSTPULSE configuration. 

It then extracts the configuration’s offset, size, and XOR key. It decrypts it using the XOR algorithm, effectively hiding the malware’s configuration within the image, making it more difficult to detect and analyze.

visual breakdown of the process
visual breakdown of the process

Researchers enhanced the configuration extractor to accommodate both GHOSTPULSE versions, which refined the tool to process PNG files and extract their embedded payloads. 

The updated YARA rules for GHOSTPULSE detection, released by Elastic Security, are designed to identify the malware’s second stage of infection, which will be incorporated into Elastic Defend in a future update, focusing on specific byte sequences within the malware’s executable. 

Rule Windows_Trojan_GHOSTPULSE_1 targets unique byte patterns found in the second stage, while rule Windows_Trojan_GHOSTPULSE_2 identifies a specific sequence of instructions related to the malware’s execution flow.

These rules effectively prevent the malware from completing its malicious activities by detecting these patterns.

The GHOSTPULSE malware family has undergone significant evolution since its 2023 debut, as the recent update represents a major overhaul, demanding adaptive countermeasures from defenders. 

The landscape of cyber threats is constantly shifting, and to keep up with the changes, collaboration and innovation are still necessary for secure protection.

How to Choose an ultimate Managed SIEM solution for Your Security Team -> Download Free Guide (PDF)

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

Kali Linux 2025.2 Released: New Tools, Smartwatch and Car Hacking Added

Kali Linux, the preferred distribution for security professionals, has launched its second major release...

Arsen Launches AI-Powered Vishing Simulation to Help Organizations Combat Voice Phishing at Scale

Arsen, the cybersecurity startup known for defending organizations against social engineering threats, has announced...

NIST Releases New Guide – 19 Strategies for Building Zero Trust Architectures

The National Institute of Standards and Technology (NIST) has released groundbreaking guidance to help...

Spring Framework Flaw Enables Remote File Disclosure via “Content‑Disposition” Header

A medium-severity reflected file download (RFD) vulnerability (CVE-2025-41234) in VMware's Spring Framework has been...

Credential Abuse: 15-Min Attack Simulation

Credential Abuse Unmasked

Credential abuse is #1 attack vector in web and API breaches today (Verizon DBIR 2025). Join our live, 15-min attack simulation with Karthik Krishnamoorthy (CTO - Indusface) and Phani Deepak Akella (VP of Marketing - Indusface) to see hackers move from first probe to full account takeover.

Discussion points


Username & email enumeration – how a stray status-code reveals valid accounts.
Password spraying – low-and-slow guesses that evade basic lockouts.
Credential stuffing – lightning-fast reuse of breach combos at scale.
MFA / session-token bypass – sliding past second factors with stolen cookies.

More like this

Kali Linux 2025.2 Released: New Tools, Smartwatch and Car Hacking Added

Kali Linux, the preferred distribution for security professionals, has launched its second major release...

NIST Releases New Guide – 19 Strategies for Building Zero Trust Architectures

The National Institute of Standards and Technology (NIST) has released groundbreaking guidance to help...

Spring Framework Flaw Enables Remote File Disclosure via “Content‑Disposition” Header

A medium-severity reflected file download (RFD) vulnerability (CVE-2025-41234) in VMware's Spring Framework has been...