Skip to main content
← Back to Demos
Extension Mismatch intermediate · 15 min

PNG Magic-Byte Spoof — Helix/Delek US & Gunra Payloads Hidden Behind a Forged Image Header

In August 2026, extortion crews such as the Helix group (behind the Delek US petroleum-refiner breach) and the China-linked UAT-10147 cluster routinely smuggle stage-2 payloads past perimeter controls by forging the file's magic bytes — the leading signature bytes — to mimic a benign PNG image, while the real payload is a shell script or ELF binary. Naive allowlists that trust only the header signature (e.g. checking for 0x89 'PNG') or the file extension pass the disguised payload straight to the endpoint, where it detonates as a loader for ransomware such as Gunra. This demo reproduces the technique safely: a benign, calculator-only bash script is prepended with a genuine PNG header so the file masquerades as an image. MetaDefender FileType Engine inspects the actual internal structure rather than trusting the forged header, flags the declared-vs-real format mismatch, and blocks the file before execution — the same control that would have neutralized the Helix/Delek US drop and the UAT-10147 SPECTRE delivery chain referenced in the CISA-adjacent CVE-2026-69836 Entra ID patch cycle.

Attack Technique

Magic-byte spoofing to masquerade as a PNG image (T1036.005)

MITRE ATT&CK

T1036.005 ↗

Platforms

linux

File Types

.cmd.png

MetaDefender Capabilities

FileType Engine

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---