Security expert spotted a new piece of malware that leverages weaponized Word documents to download a PowerShell script from GitHub. Malware uses steganography to hide the malicious code in the image. Once decoded, the script reveals a Cobalt Strike payload that allows attackers to deploy beacons on compromised Windows machines. The code uses an EICAR string to evade the detection by tricking the defense into thinking that the code is used as part of a security test. The payload receives instructions from the C2 via a WinINet module.”]
Source: https://securityaffairs.co/wordpress/112972/hacking/muddywater-attack-github-imgur.html

