Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Shadow AI’s Real Threat Is Access Control

June 26, 2026

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

June 26, 2026

The Security Coverage Gap is a Math Problem

June 26, 2026
Facebook X (Twitter) Instagram
Saturday, June 27
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»FileFix Campaign Using Steganography and Multistage Payloads
News

FileFix Campaign Using Steganography and Multistage Payloads

Team-CWDBy Team-CWDSeptember 17, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A rare in-the-wild FileFix campaign has been observed by cybersecurity researchers, which hides a second-stage PowerShell script and encrypted executables inside JPG images.

The attack, detailed in an advisory by Acronis, persuades victims to paste a malicious command into a file upload address bar, then runs a heavily obfuscated PowerShell chain that downloads and parses images to extract payloads.

What’s new in this instance is that the campaign departs from the original attack proof of concept (POC). ClickFix-style attacks have surged recently by over 500% and a FileFix proof of concept was published in early July by researcher Mr. d0x.

This particular deployment, however, is the first seen in the wild that does not strictly follow that POC and instead uses multilingual phishing pages, heavy JavaScript minification and steganography to conceal code.

Phishing Infrastructure and Social Engineering

According to Acronis, the phishing site mimics a Meta support page and pressures users into an appeal flow that asks them to “open File Explorer” and paste a path that is actually a payload.

The site includes translations for 16 languages and multiple variants have been active in the last two weeks, indicating rapid iteration and global targeting.

The social engineering element of FileFix may prove more persuasive than ClickFix, as most users are familiar with file upload windows, but not with terminal prompts. This subtle shift demonstrates how attackers are refining lures to align with everyday user behavior.

Read more on steganography: Threat Actors Target Victims with HijackLoader and DeerStealer

Multistage Delivery and Final Payload

The attack infection chain begins with an obfuscated PowerShell one-liner that reconstructs variables, downloads an image hosted on BitBucket and extracts a plaintext second-stage script from a defined byte range. 

That script uses RC4 decryption and gzip decompression to carve multiple files from the image, execute EXEs via conhost.exe and then remove them.

The final loader, written in Go, carries out sandbox checks by comparing hardware information, then decrypts shellcode leading to the deployment of StealC. 

This infostealer is capable of harvesting data from browsers, cryptocurrency wallets, messaging apps and cloud services. Researchers note that StealC can also act as a downloader, giving attackers flexibility to deliver additional malware.

Detection and Mitigation

Key recommendations from Acronis researchers center on strengthening both user training and technical defenses.

Organizations are encouraged to take a layered approach that combines awareness with proactive blocking measures, including:

  • Teach users to avoid pasting commands into system dialogs or file upload address bars

  • Block PowerShell, CMD, MSIEXEC or MSHTA processes launched from web browsers

  • Monitor for unusual browser-child process activity across endpoints

The campaign highlights how quickly FileFix has evolved from a proof of concept to an active threat.

By blending social engineering, obfuscation and steganography, attackers are making detection more difficult. Security teams must stay alert and ensure users understand these emerging *Fix attack techniques.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleHow Leading CISOs are Getting Budget Approval
Next Article Critical CVEs in Chaos-Mesh Enable In-Cluster Code Execution
Team-CWD
  • Website

Related Posts

News

Shadow AI’s Real Threat Is Access Control

June 26, 2026
News

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

June 26, 2026
News

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How to tell if a voice call is AI or not

February 23, 2026

When ‘hacking’ your game becomes a security risk

October 17, 2025

2025’s most common passwords were as predictable as ever

January 21, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.