Skip to main content
← Back to Demos
Steganography intermediate · 15 min

Malware payload hidden inside ordinary image file (steganography)

Microsoft removed 119 malicious Edge extensions that hid malware payloads inside ordinary image and font files using steganography; the extensions, which included ad blockers, VPNs, and video downloaders, combined ad fraud with credential theft and reached a combined install base of up to 2.6 million users. Steganography defeats scanners because the payload is embedded in the least-significant bits of a picture: the image renders normally, hashes cleanly, and matches no known signature, while the hidden data is released only when the loader extracts it at runtime (MITRE T1027.003). Deep CDR decodes and re-encodes images, stripping non-image data and rebuilding a clean picture that carries nothing hidden. The demo uses a benign image with a harmless hidden text message, so it is safe to open and inspect in any environment.

Attack Technique

Steganographic payload in image

MITRE ATT&CK

T1027.003 ↗

Platforms

linuxwindows

File Types

.png

MetaDefender Capabilities

Deep CDR

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---