S0231

S0231Invoke-PSImage

ATT&CK
14.1
References
2

Description

[Invoke-PSImage](https://attack.mitre.org/software/S0231) takes a PowerShell script and embeds the bytes of the script into the pixels of a PNG image. It generates a one liner for executing either from a file of from the web. Example of usage is embedding the PowerShell code from the Invoke-Mimikatz module and embed it into an image file. By calling the image file from a macro for example, the macro will download the picture and execute the PowerShell code, which in this case will dump the passwords. (Citation: GitHub Invoke-PSImage)

References

  1. https://attack.mitre.org/software/S0231
  2. https://github.com/peewpw/Invoke-PSImage

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
Invoke-Mimikatz
Sub-technique
Steganography
Sub-technique
PowerShell
Software
PowerSploit
Software
PsExec
Software
PowerShower
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.