TerminalFix PNG Steganography

Executive Summary

Microsoft Security Research blog post details the TerminalFix campaign, which deploys a reverse tunnel through a multistage intrusion. Threat actors embed malicious payloads in PNG files using steganography. Researchers have released IOCs for these PNG files.


Intelligence Metadata - Source Publisher: SANS Internet Storm Center - Published Date: 2026-09-21T10:33:53+00:00 - Category: threat-intel

Original Description: Microsoft Security Research published an interesting blog post "TerminalFix campaign deploys a reverse tunnel through multistage intrusion" about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganography. I reached out to the researchers and they kindly shared the IOCs for the PNG files with me.

"Though no one can go back and make a brand new start, anyone can start from now and make a brand new ending."

— Unknown
Source: SANS Internet Storm Center