Worok Hackers Use Steganography to Hide New Malware from PNGs

A threat group known as “Worok” hides malware in PNG images to infect victims’ computers with information-stealing malware. Alarms are not raised. Researchers at Avast have confirmed this, building on the findings of ESET who were the first to report on Worok activity in September 2022.


ESET warned Worok that it targeted high-profile victims including government agencies in the Middle East and Southeast Asia. However, their visibility into the attack chain was very limited.

new malware from PNGs
Next >>