Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit JPEG Files to Spread Malware

Hackers Exploit JPEG Files to Spread Malware

Posted on May 11, 2026 By CWS

In a newly identified cyberattack, hackers are leveraging seemingly innocent JPEG files to infiltrate Windows systems with malware. This sophisticated operation, dubbed Operation SilentCanvas, disguises a malicious PowerShell script as a JPEG image, granting attackers stealthy control over compromised machines.

How the Cyberattack Unfolds

The attack initiates when a targeted user receives a file named sysupdate.jpeg via phishing emails, misleading software updates, or deceptive file-sharing links. Despite its JPEG extension, the file contains no actual image data. Instead, it harbors a PowerShell script designed to establish a staging environment and download further harmful components from servers controlled by the attackers.

Security researchers at Cyfirma have traced this attack’s progression, highlighting its reliance on a combination of advanced techniques to evade detection and deepen system infiltration. The malicious file, once executed, leads to the deployment of a trojanized version of ConnectWise ScreenConnect, a legitimate remote access tool. This altered software provides a hidden backdoor, blending seamlessly with trusted applications.

Technical Breakdown of the Attack

The file sysupdate.jpeg lacks the standard image header, enabling it to bypass Windows script detection. When activated, it creates a hidden directory and downloads a compromised ScreenConnect package from legitserver.theworkpc[.]com using TCP port 5443. The malware employs runtime string reconstruction to avoid antivirus detection, and a secondary payload, access.jpeg, is executed directly in memory, leaving no trace on the disk.

The attack chain further involves the Microsoft .NET compiler, csc.exe, which builds a custom launcher named uds.exe on the victim’s machine. This approach ensures each binary has a unique signature, thwarting signature-based scanning efforts.

Post-Compromise Consequences

Once operational, the trojanized ScreenConnect tool allows attackers extensive control over the victim’s system. Capabilities include real-time screen monitoring, video and audio capture, keystroke logging, and encrypted file transfers to evade network inspections. Additionally, a hidden Windows service named OneDriveServers ensures malware persistence across system reboots.

Attackers can intercept credentials at the login screen and create hidden administrator accounts for sustained access. Security teams are advised to monitor execution of commonly abused Windows binaries, enforce strict remote access controls, and implement detection rules for suspicious PowerShell activity.

Security Recommendations and Future Outlook

Organizations are encouraged to block or closely monitor execution of binaries like csc.exe and ComputerDefaults.exe, and to reset credentials for all privileged accounts following potential exposure. The detailed indicators of compromise (IoCs) provided can assist in identifying affected systems and preventing further breaches.

As cyber threats evolve, staying informed about attack methodologies and maintaining robust security practices is crucial for safeguarding digital assets. Regular updates and vigilance remain key defenses against such advanced cyber threats.

Cyber Security News Tags:cyber attack, Cybersecurity, JPEG attack, Malware, Phishing, PowerShell, remote access, ScreenConnect, security defenses, Windows systems

Post navigation

Previous Post: Skoda Online Shop Faces Significant Data Breach
Next Post: Linux Rootkit and macOS Crypto Stealer Dominate Headlines

Related Posts

Critical Bing Images Flaws Patched Amid Security Concerns Critical Bing Images Flaws Patched Amid Security Concerns Cyber Security News
How a Faulty Windows Driver Can Cause a System Crash and Blue Screen of Death How a Faulty Windows Driver Can Cause a System Crash and Blue Screen of Death Cyber Security News
HackerOne Confirms Data Breach – Hackers Gained Unauthorized Access To Salesforce Instance HackerOne Confirms Data Breach – Hackers Gained Unauthorized Access To Salesforce Instance Cyber Security News
DrayOS Routers Vulnerability Let Attackers Execute Malicious Code Remotely DrayOS Routers Vulnerability Let Attackers Execute Malicious Code Remotely Cyber Security News
New Windows-Based Airstalk Malware Employs Multi-Threaded C2 Communication to Steal Logins New Windows-Based Airstalk Malware Employs Multi-Threaded C2 Communication to Steal Logins Cyber Security News
HR Giant Workday Discloses Data Breach After Hackers Compromise Third-Party CRM HR Giant Workday Discloses Data Breach After Hackers Compromise Third-Party CRM Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • China-Linked Group Unleashes StormEncryptor Ransomware
  • Windows WalletService Flaw Could Lead to Privilege Escalation
  • CISA Demands Urgent Fix for Progress LoadMaster Flaw
  • AI Threats, Metabase 0-Day, and Router Backdoors Highlight Cybersecurity Concerns
  • Critical Progress LoadMaster Vulnerability Alert: Exploitation Detected

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • China-Linked Group Unleashes StormEncryptor Ransomware
  • Windows WalletService Flaw Could Lead to Privilege Escalation
  • CISA Demands Urgent Fix for Progress LoadMaster Flaw
  • AI Threats, Metabase 0-Day, and Router Backdoors Highlight Cybersecurity Concerns
  • Critical Progress LoadMaster Vulnerability Alert: Exploitation Detected

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark