National Cyber Warfare Foundation (NCWF)

PureRAT Hides PE Payloads in PNGs for Fileless Execution


0 user ratings
2026-04-21 09:24:09
milo
Red Team (CNA)

A multi-stage PureRAT campaign that hides portable executable (PE) payloads inside PNG images and executes them almost entirely in memory, making detection and forensics significantly harder for defenders. The campaign combines steganography, PowerShell-based loaders, UAC bypass, process hollowing, and anti-virtualization checks to remain stealthy on compromised systems. The attack begins with a weaponized .LNK file […]


The post PureRAT Hides PE Payloads in PNGs for Fileless Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.



Mayura Kathir

Source: gbHackers
Source Link: https://gbhackers.com/purerat-hides-pe-payloads/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.