Blog | G5 Cyber Security

GandCrab ransomware campaign targets Italy using steganography

A newly discovered malware campaign leverages steganography to hide GandCrab ransomware in an apparently innocent Mario image. Steganography is used in conjunction with heavily obfuscated Microsoft Powershell commands that have hidden within the color channels of a picture of Mario, in a particularly manipulating blue and green pixels. This technique makes the threat hard to be detected by firewall and other defence systems. Attackers are targeting users in Italy, but the campaign will likely extend to other countries worldwide. Update: Thanks to ZLab team for getting in touch and pointing out that the final EXE samples are actually Ursnif and not Gandcrab as reported above.”]

Source: https://securityaffairs.co/wordpress/80875/malware/gandcrab-ransomware-steganography.html

Exit mobile version