{"id":9411,"date":"2025-12-23T10:04:34","date_gmt":"2025-12-23T10:04:34","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/23\/hackers-using-clickfix-technique-to-hide-images-within-the-image-files\/"},"modified":"2025-12-23T10:04:34","modified_gmt":"2025-12-23T10:04:34","slug":"hackers-using-clickfix-technique-to-hide-images-within-the-image-files","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/23\/hackers-using-clickfix-technique-to-hide-images-within-the-image-files\/","title":{"rendered":"Hackers Using ClickFix Technique to Hide Images within the Image Files"},"content":{"rendered":"<p>    Hackers Using ClickFix Technique to Hide Images within the Image Files<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Threat actors have evolved their attack strategies by combining the deceptive ClickFix social engineering lure with advanced steganography techniques to conceal malicious payloads within PNG image files.<\/p>\n<p>This sophisticated approach, discovered by Huntress analysts, represents a significant shift in how cybercriminals deliver information-stealing malware to unsuspecting users.<\/p>\n<p>ClickFix operates as a <a href=\"https:\/\/cybersecuritynews.com\/bybit-hack-sophisticated-multi-stage-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">multi-stage attack<\/a> chain that tricks users into manually executing commands via the Windows Run prompt.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjOz501Mb7vbJbrvKRyg0244TmgdssES4jjAb7NbED3y7lgfXFlumfBKvo_sPNDGgsVFhnonmTcT1Wcc4tk4spJOnQeCXGoxV4-3SlO7_m56TvC5XOaPsopYFqb0k6js5TpYPHae16TSfowjP4JzFSgMKd9rsNecmmYZn0oNvfUo7K0bWykcwGnfIA_tlA\/s16000\/Human%2520Verification%2520Lure%2520%28Source%2520-%2520Huntress%29.webp?ssl=1\" alt=\"Human Verification Lure (Source - Huntress)\"><figcaption class=\"wp-element-caption\">Human Verification Lure (Source \u2013 Huntress)<\/figcaption><\/figure>\n<\/div>\n<p>The campaign begins when victims encounter convincing lures, including fake robot verification screens and realistic Windows Update notifications.<\/p>\n<p>These pages instruct users to press Win+R to open the Run box, then paste a command that has been automatically copied to their clipboard.<\/p>\n<p>Once executed, this initial command initiates a dangerous chain of events that ultimately delivers malware to the target system.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgU_KBi5f73fUc7cGQ3e_SvQnhRbXKWvTCmRgZuRpv9-sRWr4rTqUWmRuoJ1EZte_l_nfQD7e8a5Vcdb11vumLFs1gpbIEuWVn4oBlyDUycWlMVOe_pqRQ2TjoZ2mYm9s0UBz5NY4bSZJRN_vuEbY5_2F_2LyMQ8AcVtLBrPl-zn58kBKu33k_3a5S4Trk\/s16000\/Snippet%2520of%2520ClickFix%2520Lure%2520Source%2520%28Source%2520-%2520Huntress%29.webp?ssl=1\" alt=\"Snippet of ClickFix Lure Source (Source - Huntress)\"><figcaption class=\"wp-element-caption\">Snippet of ClickFix Lure Source (Source \u2013 Huntress)<\/figcaption><\/figure>\n<\/div>\n<p>Huntress analysts and researchers <a href=\"https:\/\/www.huntress.com\/blog\/clickfix-malware-buried-in-images\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the malware emerging in October 2025, with campaigns evolving across two distinct variants.<\/p>\n<p>The initial \u201cHuman Verification\u201d lures have been overshadowed by newer, more convincing fake Windows Update screens that mimic legitimate Microsoft updates in full-screen mode, complete with realistic \u201cWorking on updates\u201d animations before prompting the ClickFix command execution.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-steganographic-payload-concealment\"><strong>Steganographic Payload Concealment<\/strong><\/h2>\n<p>The most notable aspect of this campaign is how threat actors conceal their final malware stages. Rather than appending malicious data to images, the attackers use a custom steganographic algorithm to encode shellcode directly within the pixel data of PNG images.<\/p>\n<p>This technique relies on specific color channels\u2014particularly the red channel\u2014to reconstruct and decrypt the payload entirely in memory.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiZK4FZ7q1BN9-fqVtXAoXcEaCHneP-un6iha8KKUeUnmkVMBB1li8l8SYCrG4pOTMdXaBvQe4NZ6Rytc4UmmMGXSmwU-D0qZ3aP0uxGewkVtt12UHtY0i2RSDdYvEYUH5iDA2nrpLPEBiSVfPIyu1O9Zw0DpOj6GuCedmpXXUqplsEjgKDGtRuGwRyIE4\/s16000\/Execution%2520chain%2520leading%2520to%2520LummaC2%2520%28Source%2520-%2520Huntress%29.webp?ssl=1\" alt=\"Execution chain leading to LummaC2 (Source - Huntress)\"><figcaption class=\"wp-element-caption\">Execution chain leading to LummaC2 (Source \u2013 Huntress)<\/figcaption><\/figure>\n<\/div>\n<p>The infection mechanism begins with an mshta.exe command containing a hex-encoded IP address in its second octet.<\/p>\n<p>This triggers a <a href=\"https:\/\/cybersecuritynews.com\/windows-powershell-0-day-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell<\/a> loader that dynamically decrypts and reflectively loads a .NET assembly. This assembly acts as a steganographic loader, extracting shellcode hidden within an encrypted PNG image embedded as a manifest resource.<\/p>\n<p>The extraction process uses the bitmap\u2019s raw pixel data, calculating offsets for each row and column, then XORs the red channel value with 114 to recover the encrypted shellcode bytes.<\/p>\n<p>The extracted shellcode is packed using Donut, a shellcode packer that enables in-memory .NET assembly execution.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXJp8a92CbKeCSFI5qo7aUqlxOpajYk1J8XUNjHB14KBbUIAzbsB6fR3tP5z_RYPE2jFCEZZcyDFC9MQUskN0ZGzkefxoQryk-aJz8LelSeZNVslyLIxQxqz8tUWRWvldkw35B6KQpWrz5dOyCZFiFFAa0eQhYXZ8V1Ri94HCsPYEH7E0D7lLk7jaM0Xk\/s16000\/dnSpy%2520output%2520displaying%2520manifest%2520resource%2520%28Source%2520-%2520Huntress%29.webp?ssl=1\" alt=\"dnSpy output displaying manifest resource (Source - Huntress)\"><figcaption class=\"wp-element-caption\">dnSpy output displaying manifest resource (Source \u2013 Huntress)<\/figcaption><\/figure>\n<\/div>\n<p>Huntress researchers documented that the final payloads delivered through this mechanism include information-stealing malware such as LummaC2 and Rhadamanthys, designed to harvest sensitive user credentials and financial information.<\/p>\n<p>This <a href=\"https:\/\/cybersecuritynews.com\/smartapesg-campaign-leverages-clickfix-technique\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaign<\/a> demonstrates how threat actors continue to innovate their detection evasion capabilities. By hiding payloads within image pixel data rather than traditional file structures, attackers complicate analysis and evade signature-based detection systems.<\/p>\n<p>However, the attack still relies on the fundamental weakness of <a href=\"https:\/\/cybersecuritynews.com\/social-engineering-tactics\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a>\u2014convincing users to manually execute commands.<\/p>\n<p>Organizations should prioritize user awareness training and consider disabling the Windows Run box through registry modifications or Group Policy to prevent this attack vector from succeeding.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-using-clickfix-technique\/\">Hackers Using ClickFix Technique to Hide Images within the Image Files<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-using-clickfix-technique\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Using ClickFix Technique to Hide Images within the Image Files Threat actors have evolved their attack strategies by combining the deceptive ClickFix social engineering lure with advanced steganography techniques to conceal malicious payloads within PNG image files. This sophisticated approach, discovered by Huntress analysts, represents a significant shift in how cybercriminals deliver information-stealing malware [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9411","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9411"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9411"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9411\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9411"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9411"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9411"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}