PNG Magic-Byte Spoof — Helix/Delek US & Gunra Payloads Hidden Behind a Forged Image Header
In August 2026, extortion crews such as the Helix group (behind the Delek US petroleum-refiner breach) and the China-linked UAT-10147 cluster routinely smuggle stage-2 payloads past perimeter controls by forging the file's magic bytes — the leading signature bytes — to mimic a benign PNG image, while the real payload is a shell script or ELF binary. Naive allowlists that trust only the header signature (e.g. checking for 0x89 'PNG') or the file extension pass the disguised payload straight to the endpoint, where it detonates as a loader for ransomware such as Gunra. This demo reproduces the technique safely: a benign, calculator-only bash script is prepended with a genuine PNG header so the file masquerades as an image. MetaDefender FileType Engine inspects the actual internal structure rather than trusting the forged header, flags the declared-vs-real format mismatch, and blocks the file before execution — the same control that would have neutralized the Helix/Delek US drop and the UAT-10147 SPECTRE delivery chain referenced in the CISA-adjacent CVE-2026-69836 Entra ID patch cycle.
Attack Technique
Magic-byte spoofing to masquerade as a PNG image (T1036.005)
MITRE ATT&CK
T1036.005 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗